By Jackson Godwin. Cybersecurity Analyst & Penetration Tester.

The Fraud Team Explained the Scam
After I reported the incident, the bank’s cybersecurity team thanked me for refusing to provide my card details.
The investigator explained that criminals are increasingly combining deepfake technology, stolen personal information, and social engineering to create highly convincing financial scams.
Unlike traditional phishing attacks, these scams don’t rely only on fake emails or text messages.
They use realistic video and voice to gain a victim’s trust.
The Deepfake Was Only One Part of the Attack
The investigator pointed out something important.
The video itself wasn’t enough to fool me.
The criminals also knew:
- My full name.
- My address.
- My mobile phone number.
- The last four digits of my credit card.
That information made the conversation feel authentic.
Where did they get it?
Possibly from:
- Previous data breaches.
- Phishing campaigns.
- Publicly available information.
- Other stolen databases.
The deepfake created trust.
The stolen information made the trust believable.
They Wanted One Final Piece
The criminals already had plenty of information.
But they were still missing one critical detail.
My CVV.
Without it, completing certain online card transactions would be much more difficult.
Everything in the conversation had been carefully designed to persuade me to reveal those final three digits.
Fortunately, I never did.
Warning Signs of Deepfake Banking Scams
Looking back, there were several clues.
🚩 Unsolicited Video Calls
Receiving an unexpected video call claiming to be from your bank should immediately make you cautious.
If you’re unsure, end the call and contact your bank through its official channels.
🚩 Requests for Sensitive Card Information
Legitimate banks generally do not ask customers to disclose:
- Their full card number.
- Their CVV.
- One-time passwords (OTPs).
Especially not during unsolicited calls.
🚩 Pressure to Act Immediately
The caller repeatedly warned that I had only minutes to protect my account.
Creating urgency is one of the oldest—and most effective—social engineering techniques.
🚩 Avoiding Independent Verification
Every time I suggested calling the bank myself, the caller tried to discourage me.
A genuine representative should not object if you choose to verify the call using official contact details.
🚩 Small Visual Imperfections
Deepfakes continue to improve, but they may still show subtle inconsistencies such as:
- Brief lip-sync delays.
- Blurred facial movements.
- Lighting changes.
- Unnatural blinking.
These clues are not always present, and their absence does not guarantee that a video is genuine.
How to Protect Yourself
As AI technology becomes more advanced, protecting yourself requires good habits rather than good luck.
- Never reveal your CVV during an unsolicited phone or video call.
- End unexpected banking calls and contact your bank using its official number or mobile app.
- Enable transaction notifications.
- Use multi-factor authentication where available.
- Be cautious, even if the caller looks and sounds convincing.
- Remember that personal information alone does not prove someone is legitimate.
Trust should always be verified.
Frequently Asked Questions
Can deepfake videos really look that convincing?
Yes.
Modern AI tools can generate highly realistic faces, voices and facial expressions.
However, the quality varies, and not every convincing video is necessarily a deepfake.
Regardless, you should verify unexpected requests for sensitive information through trusted channels.
Would my bank ever ask for my CVV?
Policies differ between financial institutions, but unsolicited requests for your CVV or one-time passwords should be treated with extreme caution.
If in doubt, end the conversation and contact your bank using its official contact information.
What should I do if I think I’ve spoken to a scammer?
Stop the conversation immediately.
Contact your bank through official channels.
If you shared sensitive information, follow your bank’s instructions to secure your accounts and monitor for suspicious activity.
Final Thoughts
Years ago, people were told:
“Don’t trust strange emails.”
Today, the warning is much bigger.
Don’t trust a voice.
Don’t trust a video.
Don’t even trust a familiar face.
Artificial intelligence has made impersonation easier than ever.
The strongest defence is no longer recognising poor-quality scams.
It’s developing the habit of independent verification.
Because in today’s digital world…
The face on your screen may not belong to the person speaking.
And the safest question you can ask is the simplest one:
“Can I verify this through the bank’s official contact channels?”
That single question could save your identity, your credit card—and your money.
About the Author
Jackson Godwin is a Cybersecurity Consultant specialising in Vulnerability Assessment and Penetration Testing (VAPT), Governance, Risk and Compliance (GRC), ISO/IEC 27001, PCI DSS, Cloud Security, AI Security and Digital Risk Management.
Through JacksonTechnology.com.ng, he publishes cybersecurity awareness stories, ethical hacking tutorials, compliance guides and practical online safety advice to help individuals and organisations recognise cyber threats, prevent fraud and stay secure in an AI-powered world.
His mission is to make cybersecurity practical, relatable and accessible—one cyberstory at a time.






