The face on the screen is your boss. The voice is his voice. He says, “Wire the payment to this account now.” The face, the tone, the little verbal tics — everything checks out. And yet: is this real? A firm in Hong Kong never asked, and one video call cost it about 25 million dollars, as the Financial Times reported. We were raised on “seeing is believing.” Spotting deepfakes is the exact skill that phrase never taught us — because your eyes and ears have quietly stopped counting as evidence.
If the last series asked “why does it have to be this way?”, this one hands you a sharper question and the tools to answer it: is this real? We ended that series on an algorithm that doesn’t ban the ladder — it just controls what the algorithm shows you. This series takes one step further, from “what you’re shown” to “is what you’re shown even real?”
This is part one of “The Age of Verification.” No panic, no doom. Just a habit you can start today.
Key Takeaways
- Your brain treats “easy to process” as “probably true” (processing fluency), and deepfakes mass-produce exactly that smoothness.
- Generation is cheap and explosive while detection lags — advertised 90%+ accuracy can drop to ~49% on real-world footage (arXiv 2510.16556).
- Four cheap habits beat any single app: reverse-image search, artifact-spotting, provenance, and a “who/when/where” cross-check.
Why Smooth Fakes Beat Us: The Brain’s Blind Spot
Start with an uncomfortable fact about your own head. The easier a piece of information is to process, the more your brain nudges you to file it as true.
Psychologists call this processing fluency — the sense of mental ease when something goes down smoothly. Reber and Schwarz showed back in 1999 that statements which are simply easier to read get judged as more likely to be true. Ease feels like truth.
Now look at what a good deepfake is. It is a machine for manufacturing that ease at scale — a clean, seamless, frictionless image that slides past your guard precisely because nothing about it feels like effort.
That is the deep reason spotting deepfakes is hard. You are not fighting a bad forgery; you are fighting your own wiring, tuned long ago to trust the smooth and doubt the clumsy.
Hold onto the metaphor for the whole series: the smooth fake versus the rough real. Fakes arrive polished. Reality often shows up rough, awkward, and slightly inconvenient — and that roughness, it turns out, is a clue.
The Asymmetry Behind Spotting Deepfakes
Here is the structural problem. Making a fake is cheap and instant; catching one is slow and unreliable. The two sides are not running the same race.
FIG. 01 — WHY FAKES WIN THE RACE
Generation is cheap, detection lags
GENERATE
Cheap and instant
A convincing fake face or voice now takes minutes and near-zero cost. Online deepfakes jumped from ~500K (2023) to ~8M (2025) by one vendor's estimate.
SPREAD
Compressed and re-shared
Social feeds and video calls squeeze the file through H.264 compression, wiping out the tiny artifacts detectors rely on.
DETECT
Always a step behind
Tools advertised at 90%+ accuracy can fall to ~49% on footage outside their training data. Generation keeps outrunning detection.
SOURCE: DeepStrike (est.); arXiv 2510.16556; CJR 2025
On the generation side, volume is exploding. One security vendor, DeepStrike, estimates online deepfakes grew from roughly 500,000 in 2023 to around 8 million in 2025 — a vendor estimate, so hold the exact figure loosely, but the direction is not in doubt.
On the detection side, the numbers are humbler than the ads. Vendors love to quote 90%-plus accuracy, but that is on clean, uncompressed benchmarks.

When the Detector Meets the Real World
Push a detector onto content it wasn’t trained on and accuracy can collapse — FaceForensics-style models dropping to about 49%, some older networks to 39%, per comparative reviews. Roughly a coin flip.
The culprit is mundane: compression. Every time a clip is re-shared on social media or squeezed through a video call, H.264 compression scrubs away the tiny artifacts detectors depend on. Researchers have also flagged detection bias across skin tone and gender.
This is why “the detection app will protect me” is a dangerous comfort. It is a smoke alarm that works best in a lab and worst in your actual kitchen. Provenance systems like C2PA — cryptographic “birth certificates” for images — are growing, but they are not a finished shield yet. Which is why spotting deepfakes still comes down to a human habit, not a magic button.
The Damage Is Already Here — and It Speaks Korean
This is not a Silicon Valley problem you can watch from a distance. Korea is on the front line, and the target is often a family member.
FIG. 02 — THE DAMAGE IS ALREADY LOCAL
Voice phishing in Korea, Q1 2025
53M won
average loss per voice-phishing case (Korea, Q1 2025)
311.6B won
total Q1 2025 voice-phishing losses
2.2x
vs. the same quarter a year earlier
53%
victims aged 50 and over
SOURCE: Korean National Police Agency & Financial Supervisory Service
Voice-phishing losses in Korea reached 311.6 billion won in the first quarter of 2025 — about 2.2 times the same quarter a year earlier — with an average loss of 53.01 million won per case, according to the National Police Agency and the Financial Supervisory Service. Victims aged 50 and over made up 53%, and authority-impersonation scams 51%.
The synthetic-media version is here too. A report by the Korea Communications Agency (KCA) described a deepfake investment ad impersonating a well-known author, Park Soon-hyuk, that led one victim to transfer about 66 million won, plus a separate case impersonating the former news anchor Sohn Suk-hee.

Globally the trend points the same way, though the figures vary wildly by source and method. Deloitte forecasts that generative-AI-enabled fraud in the U.S. could climb from 12.3 billion dollars in 2023 to 40 billion by 2027 — a projection, not a measurement. The FBI’s IC3, meanwhile, counted about 893 million dollars in AI-linked fraud losses in 2025, the first year it tracked AI as its own category.
Read those two figures side by side and the honest takeaway is not “the sky is falling.” It is narrower and more useful: the damage is real, measurable, and already local.
Spotting Deepfakes in Practice: Four Habits
Here is the part you can actually use. Spotting deepfakes is less about one clever trick and more about four cheap habits you run in order.
Look, Then Look Sideways
Reverse-image search first. Drop the picture into Google Lens or TinEye and ask where it first appeared. A “breaking” photo that traces back three years, or to a stock library, answers itself.
Read the artifacts. Fakes get sloppy in small places — count the fingers, check the ears and teeth, watch reflections in glasses, follow the light direction and the hairline, and see whether the lips truly match the sound. The rough details are where the smooth fake cracks.
FIG. 03 — SMOOTH FAKE VS. ROUGH REAL
Where fakes get sloppy
Deepfake artifact (too smooth / off)
Genuine footage (often rougher)
Extra or fused fingers, edges that warp
Natural, sometimes awkward but consistent frame to frame
Blurred ear, shifting teeth, reflections that don't match
Small imperfections that stay stable across frames
Audio slightly off from the mouth movement
Voice and lips locked together, even on hard sounds
Light direction disagrees; hairline smears into the background
Stray hairs and shadows that agree with the scene
SOURCE: Columbia Journalism Review 2025
Trace It, Then Ask Out Loud
Check provenance. Look for content credentials, watermarks, metadata, and the original source. The signal is real but one-sided: its presence is reassuring, its absence proves nothing. Treat “no credential” as “unknown,” not “fake.”
| Device / platform | C2PA milestone | What it means |
|---|---|---|
| Leica M11-P (Oct 2023) | First consumer C2PA camera | signs images at capture |
| Samsung Galaxy S25 | First major phone to adopt it | credentials on mobile |
| Google Pixel 10 (Sep 2025) | Signs every photo via a hardware key | provenance by default |
| Nikon Z6 III | Certificate suspended after a signing flaw | present ≠ trustworthy |
Ask “who, when, where” — then cross-check. Has another trusted outlet reported the same thing? And here is the practical nerve of family-impersonation defense: if a message urgently demands money or a password, hang up and call back on a channel you already trust. Urgency itself is the tell.
Notice that none of this requires a lab. It requires a five-second pause — the exact pause the fake is engineered to rush you past.
Verification Is a Habit, Not Suspicion
It is tempting to read all this and slide into “trust nothing, everyone’s lying.” That is the wrong exit, and a lazy one.
Verification is not cynicism. It is the opposite — a method for believing well, so that your trust lands on the things that actually earn it. You check a bridge before you drive across it not because you hate bridges, but because you intend to cross.
So make it small and repeatable. One reverse-image search. One glance at the hands. One call back on a trusted line. Done often enough, it stops being work and becomes reflex.
Next in the series: we move from eyes and ears to the written word — because the more flawless the grammar, the more you should slow down. If your eyes can be fooled, your reading can too.
Bottom Line. In an age when anything can be made to look real, the smooth thing is the suspicious thing — and spotting deepfakes is less a tech skill than a five-second habit of asking “is this real?”
Everyday Takeaway. The next time a face or voice on a screen urgently wants money or a password, run one check before you act: reverse-image, artifacts, provenance, or a call back on a channel you trust. Verification is not doubt — it is method.
Frequently Asked Questions (FAQ)
Q. What is the single fastest way to start spotting deepfakes? A. Slow down for five seconds and do one reverse-image search. Drop the image into Google Lens or TinEye and check where and when it first appeared. Most viral fakes fall apart the moment you find their real origin, and the pause alone breaks the urgency that scams depend on.
Q. Can a detection app just do the verification for me? A. Not reliably on its own. Detectors advertised at over 90% accuracy can fall to around 49% on compressed, real-world footage that sits outside their training data, according to comparative research. Treat an app as one weak signal among several, not as a verdict, and pair it with provenance and cross-checking.
Q. If an image has no content credential, does that mean it is fake? A. No. Provenance standards like C2PA are still rolling out, and metadata is easy to strip or lose in re-sharing. A credential’s presence is reassuring, but its absence only means “unknown.” Judge missing provenance as a reason to check further, not as proof of a fake.
References
- Deloitte — Deepfake Banking Fraud Risk on the Rise
- Deepfake Statistics 2025 — DeepStrike
- What Journalists Should Know About Deepfake Detection in 2025 — Columbia Journalism Review
- Fit for Purpose? Deepfake Detection in the Real World — arXiv 2510.16556
- Effects of Perceptual Fluency on Judgments of Truth (Reber & Schwarz) — PhilPapers
- C2PA Adoption Tracker 2026 — Editors Weblog
- C2PA Cameras & Phones 2026 — AttestTrail
- Korean National Police Agency & FSS — Q1 2025 Voice Phishing Losses (KRW 311.6bn), via Segye Ilbo
- Korea Communications Agency (KCA) Media Issue & Trend Vol.60 — Deepfake Investment Scam Ads
The Verification Age — Series
- Part 1. Spotting Deepfakes: When Seeing Stopped Being Proof (this article)
- Part 2. Verifying AI Content: Why Fluent Never Means True
- Part 3. The Quiet Skill of Vetting Expertise: A Title Is Not the Truth
- Part 4. How Statistics Lie: Six Questions to Catch a Chart in the Act
- Part 5. Verifying Your Own Judgment: The Easiest Person to Fool Is You
Action sequel to The Anatomy of Naturalization series — from spotting the arbitrary to testing what is real.
