Ten seconds of recorded speech can be enough to clone an executive’s voice, and basic face-swapping tools are available for little or no cost. More advanced systems are sold as part of a much larger criminal market. According to reporting based on Group-IB research, specialized face-swapping software used by large-scale fraud operations can cost between $1,000 and $10,000 to rent.
The same market serves two very different types of fraud. Cheap tools support mass campaigns, including scam ads, fake accounts, and automated calls. More expensive services are used in targeted attacks against people who can approve payments or grant access to company systems.
Once faces and voices can be bought this easily, impersonation becomes more than a cybersecurity issue. It affects ad review, brand safety, and the way advertisers work with testimonials, public figures, and synthetic presenters.
To understand the risk, it helps to look at the market behind it: what these services cost, how they are used in advertising, who deals with the damage, and what advertisers now need to prove before a campaign can run.
Too Long; Didn’t Read
- Deepfake tools range from free face-swapping apps to specialized systems rented for thousands of dollars.
- Cheap tools support mass fraud, including scam ads and fake account registrations. More expensive services are used in targeted attacks on employees who can approve payments.
- A familiar face or voice is no longer proof of identity. Sensitive requests should be confirmed through a trusted second channel.
- Advertisers using real people in creatives need documented consent. AI-generated people must be labeled where required, including under the EU AI Act.
What Deepfake Services Cost in 2026
Group-IB’s Weaponized AI research, published in January 2026, gives a sense of how shockingly cheap these services have become. The company monitored dark-web forums and underground marketplaces from 2022 through September 2025.
At the low end, a synthetic identity kit containing an AI-generated video actor, a cloned voice, and biometric data can cost as little as $5.
Voice-cloning subscriptions are available for under $10 a month, while deepfake image services typically cost between $10 and $50. Criminal LLM subscriptions range from $30 to $200 a month.
The most expensive option is software that swaps a person’s face in real time during a video call. Renting it can cost anywhere from $1,000 to $10,000.
Those prices reflect two very different types of fraud. Cheap tools are built for volume: thousands of fake ads, account registrations, or identity-verification attempts. Live face swapping is more likely to be used against a specific employee who can authorize a large payment.
Creating a convincing voice clone does not require much source material. Group-IB says ten seconds of usable audio may be enough. A webinar, social media clip, or recorded phone call can provide it. For any executive who regularly speaks in public, that material is already easy to find.
Prices Reported in Underground Listings
| Reported price | Service category observed by researchers | Why it matters |
|---|---|---|
| From $5 | Synthetic identity materials, including generated video, voice, and biometric data | Fake accounts and identity materials can be produced at scale |
| Under $10/month | Voice-cloning services | Voice impersonation is accessible without specialist equipment |
| $10–$50 | Deepfake image services | Fake endorsements and scam creatives are cheap to produce |
| $30–$200/month | Criminal LLM services | Scam copy and localized campaigns can be generated in large volumes |
| $1,000–$10,000 | Specialized face-swapping systems | More advanced operations can use synthetic identities in real time and at greater scale |
These figures are asking prices observed in underground listings, not verified transaction prices. They are included to show how accessible different forms of impersonation have become.
Sources: Group-IB, Weaponized AI, January 2026, and reporting based on the same whitepaper.
Three Ways Criminals Use a Borrowed Identity
The technology is similar, but the business model changes depending on the target.
Fraudulent Payments
In CEO deepfake fraud, an attacker impersonates an executive during a short call and asks an employee to make an urgent, confidential transfer.
Engineering firm Arup lost $25 million in such a scheme in Hong Kong. The company confirmed in May 2024 that an employee had joined a video meeting in which the apparent colleagues were all fabricated.
The FBI described the same method in a July 2026 advisory: fraudsters generated video for real-time conversations in which they posed as company executives, law-enforcement officers, and other authority figures.
Scam Ads
Here, attackers usually borrow a celebrity’s face to send people to a fake investment service or prize-claim page.
In June 2026, Bitdefender reported more than 9,000 malicious YouTube livestreams linked to compromised creator accounts and over 350 scam domains. Some stolen accounts had accumulated billions of lifetime views, giving scammers an audience and a layer of credibility.
A typical campaign takes over an established channel, rebroadcasts a genuine interview, and adds a QR code or link leading to the scam.
Fake Accounts
In other cases, the goal is not to impersonate a particular person but to create an identity that can pass a bank’s onboarding checks.
Group-IB recorded 8,065 deepfake attempts against the digital onboarding process of one financial institution between January and August 2025. Entrust’s 2026 Identity Fraud Report found that deepfakes accounted for one in five biometric fraud attempts. Injection attacks, which place synthetic content directly into the capture stream, rose by 40% year over year.
Deloitte has estimated that generative AI could increase fraud losses in the United States from $12.3 billion in 2023 to $40 billion by 2027. This projection was published in 2024, not a current loss figure, but it shows the expected direction of the market.
Who Pays for an Impersonation Campaign
The person who sends the money is not the only one who pays. The effects can reach well beyond the victim. The impersonated brand has to deal with the fallout, while other advertisers in the same vertical may face closer scrutiny.
Financial Aspect
For a company targeted by CEO fraud, the immediate loss may be a fraudulent transfer. The longer-term cost is operational. Payment approvals have to be reviewed, employees retrained, and access rules tightened. A process that once relied on recognizing a familiar face or voice has to be rebuilt around independent verification.
Reputational Aspect
Brands face a different problem. Scammers can combine a company’s name and products with an AI-generated celebrity endorsement, making the entire offer look real. Customers may contact the company about a giveaway, investment scheme, or product it never promoted. Some will ask for refunds. Others may post complaints naming the real brand because its logo or products appeared in the ad.
- This happened to Le Creuset in 2024. Scammers ran AI-generated ads featuring a fake Taylor Swift, who appeared to offer free cookware sets. The ads used Swift’s likeness and cloned voice, then sent users to a page where they were asked to pay a shipping fee. Le Creuset had to clarify that it was not involved in the promotion.
The campaign borrowed trust from both sides. Taylor Swift made the message feel personal, while the Le Creuset name made the offer look credible. Neither had anything to do with the campaign, but both became part of the explanation once people started asking whether the giveaway was real.
- Corporate identities can be used in the same way. Scammers created a deepfake of Binance executive Patrick Hillmann and used it during Zoom meetings with blockchain projects.
The fake executive claimed to represent Binance and discussed token listings, turning an employee’s face into a convincing version of an official company service.
- WPP faced a similar attempt in 2024. Fraudsters created a fake WhatsApp account using CEO Mark Read’s photo, arranged a Microsoft Teams meeting, and combined a clone of his voice with publicly available YouTube footage.
They then asked an agency leader to help set up a new business and tried to obtain money and personal information. The attack failed because WPP employees questioned the request.
Even when a brand does not lose money directly, it still has to deal with the campaign. Teams need to collect evidence, report ads and domains, respond to customers, publish warnings, and explain which accounts and communication channels are genuine.
Copies of the ad may continue circulating after the original has been removed, turning a single incident into an ongoing monitoring and reputation-management problem.
Platforms Are Taking Action
And it’s not just in theory. In 2026, Meta took legal action against several advertisers accused of impersonating celebrities and brands.
One operation used deepfakes of a well-known physician to promote unauthorized healthcare products. Another advertised heavily discounted Longchamp products, collected customers’ payment details, and enrolled them in unauthorized recurring charges. Longchamp said it invests significant resources in fighting fraud and counterfeiting that misuse its brand.
The Consequences for Advertisers
Other advertisers feel the impact as well. When platforms see a rise in celebrity impersonation, fake testimonials, or fraudulent offers in a particular industry, they may apply stricter checks across the category.
Campaigns using real spokespeople, customer stories, before-and-after claims, or strong promotional language can face longer reviews and additional documentation requests.
That makes consent records and source files part of the campaign workflow. Advertisers should be ready to show who appears in a creative, whether that person approved the use of their likeness, where the media came from, and which claims they agreed to endorse.
Agencies and affiliates need the same checks for assets supplied by clients or third parties. If the creative runs from their account, they may still be asked to show where it came from and confirm that they have permission to use it.
One impersonation campaign therefore spreads the cost across several parties. Victims lose money or credentials. Brands deal with customer confusion, takedowns, and reputational damage. Advertisers face tighter scrutiny and more paperwork. Platforms investigate and remove the abuse. The attacker may disappear quickly, but everyone else is left to clean it up.
How Scam Ads Reach an Audience
On poorly moderated ad networks and other loosely controlled channels, impersonation campaigns may reach users even after an initial review. Attackers can submit a harmless-looking creative and landing page, then replace the destination or show fraudulent content only to selected users once the campaign is live.
This practice, known as cloaking, is why effective ad safety requires both pre-launch moderation and continuous post-launch monitoring.
According to the PropellerAds Ads Safety Report 2025, the platform rejected more than 729,794 campaigns during moderation, 35% more than in 2024. Cloaking was involved in over 80% of confirmed advertiser suspensions.
Stolen advertiser and creator accounts make distribution easier. A compromised account comes with an established history and, in some cases, a working payment method. That is why ad account credentials trade as a commodity and why established YouTube channels are frequent targets.
Keeping this kind of content out takes checks at every stage. Advertiser verification helps block suspicious accounts before they can launch a campaign. Moderation reviews the ad and landing page before approval, while post-launch monitoring catches redirects, cloaking, and other changes made after the campaign goes live.
What Advertisers Need to Prove
For advertisers, the biggest issue is often having the right documents ready.
Google requires advertisers to prove they have permission to use a public figure’s name, face, voice, or video in an endorsement. If that proof is missing, Google may suspend the account immediately. To appeal, the advertiser may need to provide a contract, written consent, or a public statement confirming that the endorsement is genuine.
If a real person appears in a creative, keep a signed release that clearly identifies the person, the media covered, the markets where it may be used, and the permitted dates. Store it securely, define how long you will keep it, and limit access to employees who may need it for compliance or appeals.
A label does not replace permission: platform policies still require documented consent where the character is recognizable as a real person. If the character resembles an identifiable person, obtain permission. If a testimonial is fictional, it should not use a real person’s name or likeness.
Before launch, check all third-party creative packs for borrowed faces and voices. The advertiser paying for the campaign will be expected to answer for the material, even if an outside supplier created it. Avoid “as seen endorsing” claims unless the endorsement is genuine and documented.
The 2026 Rules on AI-Generated Content
Since 2 August 2026, Article 50 of the EU AI Act has required clear disclosure of deepfake content. Providers of generative AI systems must also make synthetic output detectable in a machine-readable format, which is the purpose of provenance standards such as C2PA.
The Act uses a broad definition of a deepfake. It covers AI-generated or manipulated images, audio, and video that resemble real people, objects, places, or events and could appear authentic.
Denmark has also proposed protecting a person’s appearance and voice through copyright law. The proposal would cover realistic digital imitations and extend protection for 50 years after death.
Article 50 of the EU AI Act sets out disclosure requirements for deepfake content in ads reaching EU audiences, and platform policies may go further than local rules. Confirm local requirements before running, and keep proof of consent where a real person appears.
This is a summary of published rules, not legal advice. The exact obligations also depend on whether a company provides the AI system or publishes its output, so specific questions should go to legal counsel.
How Advertisers Can Use AI Faces Safely
Using an AI-generated person in an ad is not automatically a problem. The issue is whether viewers could mistake that person for someone real or believe they are giving a genuine endorsement.
If a creative features a real actor, customer, influencer, or public figure, the agreement should cover paid advertising, AI editing, target markets, and campaign dates. Permission to use a photo does not necessarily include the right to clone someone’s voice or change what they appear to say.
Synthetic presenters should not closely resemble a real person or claim a role they do not have. An “AI-generated” label will not make a fake testimonial, medical claim, or invented endorsement acceptable. The disclosure should also appear in the creative itself, not only on the landing page.
Before launch, check assets supplied by clients, agencies, and third-party vendors. Keep the consent records, source files, original script, and approved creative together in case the platform asks for proof.
What to Do If Your Brand Appears in a Deepfake Ad
- Save the evidence before reporting the campaign: the ad, screenshots, landing-page URL, advertiser details, and timestamps. Scammers often delete or move the campaign once it is discovered.
- Report both the ad and the website behind it. If the page collects payments or personal data, notify the hosting provider, domain registrar, and payment processor as well.
- Give customer support a clear response and publish a warning through the company’s official website or social accounts if the campaign is spreading. Customers should have a quick way to check whether an offer is genuine.
- Keep monitoring for copies after the first ad is removed. The same video may return under a different account, headline, or domain, and earlier reports can help platforms connect the campaigns.
Common Questions About Impersonation
- Is a Video Call Enough to Confirm Someone’s Identity?
No. Treat a live video call as an unverified channel. Before acting on a sensitive request, confirm it through a second channel that your company controls.
- Can We Use an AI-Generated Celebrity if We Label It?
A label answers a disclosure requirement. It is a separate question from permission: Google Ads requires verifiable consent before a real person’s name, image, video, or voice is used to suggest an endorsement.
Google requires verifiable consent before a real person’s name, image, video, or voice is used to suggest an endorsement. Get that consent before producing the campaign.
- What Should We Do if Our Brand Appears in a Scam Ad?
Report the ad and its destination to the platform, including links, screenshots, and timestamps. Publish a short notice on your own website so customer support has an authoritative page to share.
Keep a record of every incident. Repeated use of the same brand can help platforms connect and block a wider campaign.
Our guide to traffic quality and fraud prevention explains the network side of the process, while the companion article on malicious ads and brand safety covers the buyer’s responsibilities.
- Do Stolen Marketing Tools Contribute to the Problem?
Yes, mainly by helping criminals distribute the ads. Cracked software can steal session tokens and advertising-account credentials, giving attackers access to established advertiser identities.
This is one reason free marketing tools can carry a security cost.
The Bottom Line
Deepfakes do not create an entirely new problem for advertisers. They make an old one harder: proving that the people, claims, and endorsements in an ad are genuine.
As synthetic content becomes part of everyday production, advertisers need to check where each creative came from and whether they have the right to use it. This should be part of the standard pre-launch process, alongside reviewing the copy, landing page, and targeting.
Come join us on Telegram for more insights and communications with fellow affiliates!