Cybersecurity, Deepfakes, Phishing

How to spot a deepfake [Real Examples]: 10 Visual and Audio Signs Everyone Should Know in 2026

Table of Contents

96% of deepfakes online are used maliciously. Theyโ€™re being used to impersonate CEOs, pressure employees into urgent actions and manipulate financial transactions, all with AI-generated videos or voice notes that feel shockingly real.

In our recent CloudGuard webinar โ€œThe Art of Deception: Fight Back Against the Fakes,โ€ our analysts broke down the exact visual and audio cues that give deepfakes away. While attackers are getting faster and more sophisticated, the technology still struggles with certain human subtleties.

This guide explains the most reliable signs of a deepfake, based directly on the examples we demonstrated during the session.

Prefer a quick visual walkthrough?


Weโ€™ve created a step-by-step interactive demo that shows some of the most common visual signs of a deepfake.

Itโ€™s a fast way to understand what to look for, but it doesnโ€™t cover every sign or the deeper audio and behavioural cues explained below. For the full picture, we recommend reading the complete guide.

๐Ÿ‘‰ Share it with colleagues as a quick awareness resource: https://app.storylane.io/share/qas6epugt1ul

1. Teeth that change shape or look โ€œtoo perfectโ€

Teeth are one of the hardest facial features for AI to replicate.

Watch out for:

  • Teeth morphing during speech
  • Sharp or inconsistent edges
  • Teeth that look unnaturally aligned or glossy

In the webinarโ€™s deepfake of our CEO, the teeth subtly changed shape mid-sentence, a clear giveaway.

2. Unnatural blinking or eye flickering

Humans donโ€™t blink at regular intervals, AI often does.

Red flags include:

  • Rapid or mechanical blinking

  • Long periods without blinking

  • Eyes that donโ€™t track naturally

  • Flickering behind glasses

Even through eyewear, the deepfake we showcased had eye movements that simply โ€œfelt off.โ€

3. Facial marks that appear or disappear

Moles, freckles, shadows and facial lines should stay consistent.

Deepfake models often struggle with:

  • Marks vanishing frame to frame

  • New marks appearing randomly

  • Shifting shadows that donโ€™t match lighting

In our example, a beauty mark popped in and out across the video, something no real face does.

4. Lip movements that donโ€™t sync perfectly

Lip-syncing is still one of the biggest technical challenges for deepfake models.

Look out for:

  • Lip edges that flicker or blur

  • Mismatched timing between audio and movement

  • Corners of the mouth that warp during speech

The deepfake of Matt showed subtle lip-edge distortion that betrayed the generated footage.

5. Clothing or hair that warps

Attackers focus on the face, the AI struggles with everything else in frame.

Signs include:

  • Buttons that disappear

  • Collars that bend unnaturally

  • Clothing merging with skin

  • Hair that blurs into the background

In the webinar demo, a shirt button simply vanished from one frame to the next.

6. A โ€œfilter-likeโ€ smoothness over the face

Deepfakes often look like a beauty filter has been applied:

  • Skin appears flat or overly smooth

  • Fine details (pores, wrinkles, texture) are missing

  • Lighting looks too even

The entire deepfake in our demo had a subtle blur overlay, which at first glance, can be very difficult to spot.

7. Audio pauses or rhythm that doesnโ€™t match the speaker

Deepfake audio can be highly convincing, but speech cadence often gives it away.

Watch out for:

  • Pauses in unnatural places

  • Rhythms that donโ€™t match how the person normally speaks

  • Odd โ€œemphasisโ€ on random words

Our analysts highlighted that the deepfake inserted pauses in a way that completely changed the tone, something anyone who knows the speaker would find suspicious.

8. Hollow, tinny or overly โ€œpolishedโ€ audio

Beyond speech patterns, sound quality itself can be a giveaway:

  • Lack of background noise

  • Robotic undertones

  • Reverb or echo that doesnโ€™t match the environment

Even professional-grade deepfakes struggle to replicate the imperfections of real audio.

9. Inability to handle unexpected questions

A powerful real-world technique: Ask something off-topic.

AI canโ€™t improvise naturally, especially in real time. In the webinar, we showed an example of an unscripted question which was injected (โ€œWhatโ€™s your favourite chocolate?โ€).

As you can see, Mena is confused as to why the question is being asked, If it was deepfake, it wouldn’t have responded convincingly.

Humans show confusion, expression, hesitation, deepfakes donโ€™t.

10. โ€œGut feelingโ€ when something just feels off

This was one of the most common reactions in our live session. Your intuition matters.

Even if you canโ€™t articulate why:

  • The tone feels wrong

  • The behaviour seems out of character

  • The message feels too urgent or unusual

Trust your instinct and verify.

Deepfakes are getting better, but so are detection techniques

As we demonstrated during the webinar, AI detection tools can analyse micro-patterns imperceptible to humans, although their accuracy varies depending on model sophistication. Some tools flagged our sample audio immediately as fake, others misclassified it entirely.

Because of this inconsistency, organisations need:

โœ” Human awareness
โœ” Technology-backed detection
โœ” Verification processes
โœ” A zero-trust communication culture

Deepfake attacks are growing, but they are not unstoppable.

Want to train your team to spot deepfakes?

CloudGuard runs live deepfake simulations to help businesses detect impersonation attempts before they become costly incidents.

๐Ÿ‘‰ Book a tabletop exercise with our experts where we can do a deepfake simulation for your organisation. Would your team pass the test?

Author: Jonathan Hartdegen
Share:
Author: Jonathan Hartdegen
Share:

Related Resources

Who Owns Your Data? No CISO, No Problem: Microsoft Purview for SMBs
AI Cybersecurity: 8 Things Your IT Teams Need to Know In 2026
AI Cybersecurity: 8 Things Your IT Teams Need to Know In 2026 AI is changing how attackers work and how organisations manage risk. When deciding how your organisation should embrace AI, cybersecurity should be top of the consideration list. For IT leaders, a priority is control of AI tools that...
Microsoft Purview Licensing: The breakdown SMBs actually NEED
Microsoft Purview Licensing Explained: Business Premium vs E3 vs E5 If you’ve looked into Microsoft Purview and come away confused about which license you actually need, you’re not alone. It’s the single biggest blocker CloudGuard sees when SMBs and mid-sized organisations start a data governance project, not the technology, the...
Microsoft Project Perception, Explained: Why Multi-Model Security Changes Everything
Why Multi-Model Security Changes Everythingย  Six years building an agentic SOC analystย (ANSEL)ย teaches you something quickly: more data isย critical butย not the answer. Better understandingย through contextย of what it means is.ย ย  Microsoft Project Perceptionย is built on exactly that insight.ย Itโ€™sย not another security product.ย Itโ€™sย a different wayย of thinking about how AI should reason,ย with context, consequence, and...
A glowing vendor evaluation checklist on a dark purple background
Why Your Vendor Evaluation Process Is Failing You (do this BEFORE YOU SIGN)
Most vendor evaluation processes are built to survive procurement, not to protect you eighteen months after go-live. Here’s the gap almost nobody catches before signing. Outlining The Problem The majority of security technologies need 90 days just to establish an accurate behavioural baseline and fair comparison. Please remember your existing...
two men talking on a podcast posted on linkedin with a red arrow pointing towards a deepfake
Why Social Engineering Always Works: How Hackers Use Phishing & Deepfakes
Weโ€™ve all done the training, so why are attackers still getting through? Attackers no longer rely on bad spelling or suspicious links, they use AI-generated deepfakes and psychological profiling to manipulate people with astonishing precision. By exploiting the brainโ€™s emergency response system, they trigger fear, urgency, or authority to override...
Dark purple background with claude logo and words pro, team and enterprise.
Claude Business Security: Choosing the Right Account for SMBs
When I shared my last article, a few people got in touch asking for a more practical follow-up, specifically around how small teams can use Claude Pro without putting business data at risk. This piece goes step by step through exactly that. Understand what you’re actually adopting Claude Pro is...
Two analysts looking surprised. Purple cyber background with phishing hook.
What Happens After a Phishing Attack? A Real Microsoft 365 Incident Walkthrough
If your organisation thinks a password reset or MFA alone are enough, think again. In this phishing attack breakdown by CloudGuard’s SOC team, Conor and Jon reveal the reality behind an actual breach involving a UK law firm, exposing how hackers use four methods to regain access long after initial...
purple background with computer that says threat from the field in cartoon like design
Cyber Threat Trends Q1 2026: Data Theft, AI Attacks and Emerging Risks
Executive Summary Every 90 days, we review the latest cyber threat trends to identify what IT leaders should learn, where resilience gaps are widening, and what practical actions organisations should take next.ย  The first quarter of 2026 has been intense. The UK threat picture is not defined by one single...
Get In Touch

Our Cybersecurity Services Can Instantly Improve Your Businessโ€™ Security Posture

Complete the form to find out more about any of our one-off or managed cybersecurity services. Not seeing what youโ€™re looking for? Our cybersecurity consultants and MXDR experts are always on-hand to provide the guidance and support you need.