A deepfake meeting attack is a fraud in which an attacker uses AI-generated or AI-altered audio and video to impersonate a real person during a live call. Instead of a suspicious email, the victim sees and hears what looks like a familiar colleague, executive or business partner. That is a much harder lie to doubt, because people trust faces and voices far more than they trust text.
This is no longer a theoretical risk. Cybersecurity News recently described a campaign in which victims received a meeting invitation through Telegram, joined a Zoom or Teams style call, and saw an AI-generated version of a contact they knew. The attackers then claimed there was an audio problem and asked the victim to install a plugin or update. Anyone who complied installed malware able to steal wallets, credentials and Telegram accounts. The campaign was aimed at cryptocurrency users, but the technique transfers directly to any company where a request to install software, share a password or approve a payment can arrive on a call.
Why does this matter for enterprises? Because the attack did not exploit a flaw in the meeting application. It exploited human trust, and it works the same way on any platform. Meanwhile Microsoft has put a response on its roadmap: Microsoft Teams is preparing synthetic audio and video detection, tracked as Microsoft 365 roadmap ID 573451, with rollout scheduled to begin in November 2026. For IT leaders in Latin America and the US, where Teams is often the main meeting and telephony platform, this is the moment to decide how meeting identity will be verified. A mature managed cybersecurity service with SOC, SIEM and MDR is the layer that turns these new signals into action.
What is the real problem? The weak point is not the video codec, it is the decision a person makes in the moment. A convincing face on screen creates urgency and authority, and attackers add a small technical excuse, such as a broken microphone, to push the victim toward an action they would normally refuse.
It helps to understand what Microsoft is and is not building. According to the roadmap coverage, the Teams feature connects meetings to certified third-party providers that analyze the audio and video for signs of generated or altered content. The provider sends detection signals back to Teams, and Teams supplies the integration that shows those signals and supports in-meeting controls. Three limits are worth stating plainly:
Microsoft is also developing separate meeting impersonation protection, which shows warnings and risk indicators when Teams detects possible identity deception, such as a suspicious organizer or participant. The two features are complementary: one looks at the identity around the meeting, the other at the media inside it.
The practical conclusion is that a detection signal is one indicator, not proof that a participant is genuine. A missing warning must never be read as clearance.
How should an enterprise respond today, before the detection feature arrives? The controls below do not depend on any single vendor, and they work whether or not synthetic media detection is available in your tenant.
Verify out of band for any sensitive request. If someone on a call asks to install software, share credentials, change bank details or approve a payment, confirm it through a separate, known channel, such as a call back to a number already on file. Make this a written rule that nobody, including executives, can waive.
Treat "install this plugin to fix your audio" as an alert. No legitimate meeting requires an unexpected download. Train staff that this specific excuse is the signature of the campaign described above, and tell them where to report it.
Control who can join and who can present. Use lobbies, restrict external participants, and limit screen sharing and control to verified internal users. Review guest and external access settings in your Teams policies.
Use the reporting tools Microsoft is shipping. The Teams admin center is getting a feature that lets users report phishing, impersonation and scam behavior in meetings, with reports reviewed by admins in the admin center and Defender. Make sure your team knows it exists and what happens after a report.
Harden the endpoint. The payload in these campaigns is malware that steals credentials and sessions. Application control, endpoint detection and tightly limited installation rights reduce what a single mistaken click can do.
Prepare to pilot detection. When the roadmap feature reaches your tenant, ask which third-party providers are certified, what meeting data they process, where it is stored, what accuracy they claim and what the license costs, before enabling anything.
Monitor and rehearse. Feed meeting and identity logs into your SIEM, and run a tabletop exercise where a "CFO" on a video call asks for an urgent transfer.
Why act before a deepfake incident rather than after? Because the cost structure favors the attacker. Producing a convincing fake call is cheap and fast, while a single approved payment or installed backdoor can be expensive, public and hard to reverse.
Building a layered defense around meetings delivers practical returns:
None of this requires abandoning video meetings. It requires treating identity verification in a live call as a process, not a feeling, and giving security and telephony teams the same visibility they already expect for email and endpoints.
HIT Communications has supported enterprises for more than 30 years across Latin America, the United States and Europe, and we sit at the point where communications and security meet. Our Microsoft Teams Direct Routing and cloud telephony services connect Teams to the public telephone network with the call quality, carrier coverage and local support that regional operations need, so voice and meetings run on a platform you can govern.
On the security side, our cybersecurity team provides 24/7 SOC monitoring, SIEM and managed detection and response (MDR), which is where meeting reports, identity alerts and endpoint signals are correlated and acted on. For organizations without the staff to harden endpoints, review Teams policies and run user awareness programs, our IT managed services cover configuration, patching and continuous improvement.
If you are deciding how to verify participants on video calls, which Teams policies to tighten before the November rollout, or how to prepare a tabletop exercise around a deepfake request, our engineers can assess your current setup and give you a prioritized plan.
Deepfake meeting attacks show that seeing and hearing someone is no longer enough to trust them. Microsoft's planned synthetic audio and video detection for Teams, scheduled to begin rolling out in November 2026, is a welcome step, but it relies on third-party providers, has no published pricing or accuracy figures, and will produce signals, not guarantees.
The durable defense is a combination of policy and technology: out-of-band verification for sensitive requests, strict control of who joins and presents, a firm rule against installing software during calls, hardened endpoints and a team watching the signals around the clock. Organizations that put these in place now will be ready to add detection when it arrives.
If you want help turning this into a plan for your Teams environment, contact HIT Communications and speak with our team about securing your meetings and telephony.

Find out how we can transform your business. Talk to one of our experts now!
Get in touch