# Deepfake scam operating inside a larger multi-stage fraud campaign (Bolster AI analysis)

> Bolster AI describes a deepfake call as one step in a longer fraud operation: domain registered, account built, story told, and money moved in small pieces before and after the synthetic call. The post frames five stages (harvest, infrastructure, approach, call, cash-out) and recommends investigating deepfake reports as campaigns rather than as media-authenticity questions.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3217
- **ID:** TL-2026-3217
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 1 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Bolster AI's blog post 'What a deepfake scam looks like inside a larger fraud campaign' models synthetic-media fraud as a five-stage operation: (1) harvest, collecting source material and victim information; (2) infrastructure, registering domains and building accounts; (3) approach, establishing a story or pretext with the target; (4) the deepfake call itself; and (5) cash-out, where money is moved in small pieces before and after the call. The central analytic recommendation is to investigate deepfake reports as campaigns, pivoting on the surrounding domains, accounts and payment flows, rather than treating them as isolated media-authenticity questions.

Sourcing limitation: the Bolster page returned HTTP 403 to direct fetch, so only the search-index excerpt (five-stage model and campaign-investigation framing) was verified. No IOCs, CVEs, actor attribution, victim counts, losses or publish date were available from the primary source and none are asserted. Severity MEDIUM is an analyst judgement, not a source statement.

Corroborating context from Doppel (published 2026-05-18) describes a similar five-stage chain (Setup, Launch, Contact, Engagement, Compromise) in which attackers gather source audio/video, build spoofed domains and fake profiles, deliver lures via video conferencing, messaging apps, calendar invites or robocalls, and steer victims toward wire transfers, credential resets or MFA approvals. Doppel cites Gartner (62% of organizations experienced deepfake social-engineering attacks in the 12 months before mid-2025) and the Verizon 2025 DBIR (60% of breaches involve a human element). Controls recommended there include out-of-band verification, second confirmation before sensitive actions, brand monitoring and campaign-infrastructure detection. The indicators listed for this threat are behavioral campaign patterns derived from the stage model, not observed network artifacts.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1583.001 Acquire Infrastructure: Domains
- T1585 Establish Accounts
- T1684.001 Impersonation
- T1657 Financial Theft

## Sources

- [What a deepfake scam looks like inside a larger fraud campaign - Bolster AI](https://bolster.ai/blog/deepfake-scam-larger-fraud-campaign)
- [Bolster AI article (search-indexed copy)](https://bolster.ai/?p=12502)
- [Bolster AI deepfake detection platform](https://bolster.ai/platform/deepfake-detection)
- [Doppel - What is deepfake scam prevention (five-stage deepfake attack chain)](https://www.doppel.com/doppel-pedia/what-deepfake-scam-prevention)
- [Beazley - Case study: finance director who fell victim to a US$6 million deepfake scam](https://www.beazley.com/en-us/articles/six-million-dollar-scam-reveals-extent-deepfake-ai-threat)
- [DuckDuckGoose - The Deepfake Pipeline: All 6 Stages Explained](https://www.duckduckgoose.ai/blog/deepfake-pipeline)
- [Gen Digital - AI-generated personas, deepfake tactics and scam-yourself attacks](https://gendigital.com/blog/insights/research/ai-generated-personas-deepfake-tactics-scam-yourself-attacks)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3217
