
A few years ago, Rodney Gullatte Jr. ran across an online video that featured a respected local leader touting an investment in cryptocurrency.
“It looked just like him, sounded just like him,” says Gullatte, a certified ethical hacker and CEO of Firma IT Solutions. He knew this person often posted videos, but when he looked closely, he spotted an almost unnoticeable quirk in the man’s eyebrow.
“I called him,” Gullatte says. “He said, ‘My account’s been hacked.’” Gullatte wasn’t fooled, but today, he says, the technology for making these “deepfakes” is orders of magnitude better.
In the first seven months of 2025, AI-generated scams accounted for more than 9,000 complaints to the FBI’s Internet Crime Complaint Center (IC3), according to the FBI’s National Press Office. Those complaints spanned fake social media profiles, voice clones, identification documents and videos that believably depicted loved ones or public figures.
“If you do any work that involves computers, you have to pay attention to these threats and scams,” Gullatte says. “It’s a business model that works.”
A vast, worldwide network of savvy criminals exists to study and penetrate businesses’ electronic footprints, says Chris Koehn, founder of Cañon City-based cyber defense and accounting firm Second-61.
“They often pursue those entities with a fake invoice that looks perfectly aligned with the business, requests from banks that are completely legitimate looking, requests for data about the company or requests for submissions and proposals,” Koehn says. “Something we’ve seen, because we do some remote work, is fake job applicants. We verify everything.”
Small businesses may get fake messages from someone claiming to be the IRS or other government agency saying that a payment is overdue or was incorrect and must be made right away, or else the agency will take away the business’s tax ID. It could even be an email that looks like it comes from someone in the company.
All of these methods, and more, “are the Trojan horse to a cyber attack,” Koehn says.
If the Company Falls Victim to a Deepfake:
Contact a company that does forensic analysis. Gather evidence; contact cybersecurity groups and spread the word about the scam. Report the activity to ic3.gov.
Call the company’s insurance provider immediately.
Put a crisis communications plan into effect.
These criminals use data that’s available online, says Marcy Freeburg, co-owner of Walsenburg-based cybersecurity and compliance company J & M Solutions.
“It’s pretty easy using AI to grab the CEO’s voice and make them make a request to the budget person that says, ‘Hey, I know this is kind of out of sync, but I need this check cut,’” Freeburg says.
Often the request will have an urgent tone: “We really need to have this done today,” she says.
Hackers can use AI to clone voices from spam calls, voicemail messages or interviews posted on social media or websites.
“AI just needs a small sample of that voice, and they can get it to sound just like that person in any words they want,” she says.
Detection tools, such as AI metadata tags on Facebook content, can help, Gullatte says. But “deepfake defense is about strong processes, not sharp eyes,” Gullatte says.
“Deepfakes are just going to get better. You can’t depend on spotting the tells. Winning in this war is building verification habits, controls and processes.”
