Stop a fake executive from forcing an approval
Protect approvals and access from attackers posing as your executives on video and voice calls, and surface the authority play before your team acts on it.
From signals to one action your team can take.
- SyntheticVideo and voiceFace-swap and voice-clone artifacts on the executive
- HighAuthority framingRank invoked to shorten review rather than to explain the request
- DetectedIsolationMoved off-channel with instructions not to loop anyone in
- Not authorizedApprover of recordRequester is not an approver for this action at this amount
Hold the approval. Staff verify through a known channel before acting on the request.
Where Diopter sits in an approval
An impersonation runs across a whole approval, not a single moment on camera. These are the stages, and what Diopter does at each one.
Before the meeting is even taken
Executive likenesses are public: earnings calls, conference talks, webinars, podcasts. The attacker does not need access to your systems to build a convincing version of your CFO, only a calendar invite that looks plausible.
- Meeting context read ahead of the call, so an organizer with no prior correspondence is known before anyone joins
- No caller-side install and nothing for the impersonator to detect or evade
- Context only at this stage: Diopter scores the call itself, it does not police your inbox
- UnconfirmedExecutive identityVoice and face not matched to the executive on record
- SyntheticSynthetic mediaFace-swap and clone artifacts present
- DetectedAuthority and isolationRank invoked, and asked not to loop in the controller
- Not authorizedApprover of recordNot an authorized approver at this amount
The verdict, its confidence level, the signals behind it, and the transcript all land in your console, and can be forwarded to security for the cases that warrant escalation.
What Diopter looks for
Synthetic media on the executive
Score the executive's video and voice for deepfake and cloning indicators.
Authority and isolation patterns
Track the authority framing, urgency, and isolation that define an impersonation play.
Out-of-policy asks
Flag approvals, access grants, and policy exceptions that fall outside normal controls, whether or not money is involved.
Approver-of-record check
Test the request against who is actually authorized to approve it at that amount, and whether the second signature your policy requires is present.
Where executive impersonation shows up
- 01
CEO and CFO authority plays
Impersonated leaders pushing staff to approve transfers, share access, or bypass review, the pattern behind the Arup and Ferrari attacks.
- 02
Isolation and secrecy
Requests moved to private channels with just-between-us framing to remove witnesses.
- 03
Access and exceptions, not just money
The ask is often a system grant, a waived control, or a signature, which clears without ever touching a payment system and so never shows up in a fraud report.
How an executive impersonation attack unfolds
These attacks move through a recognizable sequence. Diopter scores that sequence while the call is still in progress.
The leader appears
A cloned CEO or CFO arrives on video or voice with the authority staff are wired to obey.
It cannot wait
A confidential deal or a closing window frames the request as urgent and exceptional.
Keep it between us
The executive moves the conversation off-channel and discourages looping in others.
The ask grows
A first small step is followed by a larger one, each harder to refuse than the last.
Staff act on it
A transfer, an access grant, or an exception goes through on an impersonated leader's word.
Most tools ask whether the face is fake. The play is bigger than the face.
An impersonated executive is a sequence, not a frame. Rank gets invoked to shorten review, the request moves somewhere with no witnesses, the ask grows one step at a time, and the person making it turns out not to be an approver for that action at all. A detector that only answers whether the video is synthetic misses every one of those, and a human running the same play with no deepfake at all sails straight through it. Diopter scores the media and the sequence together, and checks the ask against who is actually allowed to approve it.
Attackers can fake your CEO's face and voice. They cannot fake the absence of a real relationship and your normal way of working.
Light to deploy, clear about what runs where.
Pilot in days, roll wider through MDM, and keep sensitive call media inside your perimeter.
- On-prem and hybrid deployments supported
- No caller-side install
- Bot or bot-free capture
- Configurable retention, including ZDR
- MDM rollout (Intune, Jamf)
- SOC 2 Type II in progress
Walk an attack arc with Diopter.
We will replay a real incident, show the signals Diopter scored, and map the verdict your team would act on. We will sign your NDA first if you want one.