AI, deepfakes and bad actors: Understanding the risks
July 24, 2026 Enterprise Information Security
Learn how deepfakes and voice-cloning technology are being used in sophisticated scams — and the simple steps you can take to protect yourself and Emory’s data. Illustration created using Microsoft Copilot.
Artificial intelligence (AI) is reshaping how we work, communicate and access information. While the technology offers significant benefits, it is also being used by bad actors to create increasingly sophisticated scams. Two growing concerns are deepfakes and voice-cloning technology.
Deepfakes are AI-generated images, videos or audio recordings designed to resemble real people. Voice cloning uses a small sample of recorded audio to replicate a person’s speech patterns and create realistic-sounding messages.
It is important to distinguish between the technology and those who misuse it. Deepfakes and voice cloning are tools. Bad actors — also known as threat actors — are individuals who seek to steal information, commit fraud, disrupt operations or cause harm. Increasingly, they are using AI-powered tools to make scams more convincing and more difficult to detect.
The threat is not theoretical. Bad actors have attempted to contact Emory’s IT Service Desk while impersonating patients or students and requesting account changes. Following established identity-verification procedures and directing individuals to the appropriate self-service portals remain critical safeguards for protecting institutional data.
At the same time, AI technologies are not inherently malicious. They support a wide range of legitimate uses, including accessibility solutions for individuals who have lost their voices; educational simulations; media production; training environments; and content creation. The challenge lies in recognizing when these tools are being used to deceive.
As AI-generated content becomes more common, traditional markers of trust are no longer enough. A familiar voice or recognizable face may not always confirm a person’s identity.
Before responding to requests involving money, passwords, sensitive information or account changes:
- Verify the request through a separate, trusted communication channel.
- Follow established authentication and identity-verification procedures before making account changes.
- Report suspicious activity immediately.
- Hover over links before clicking and use Emory’s phishing reporting process to report suspicious emails.
- Escalate concerns to the Enterprise Information Security team or your supervisor when something does not seem right.
- Enable and use multi-factor authentication whenever available.
Stay alert, stay secure
Cybersecurity is a shared responsibility. By following established policies, verifying identities and reporting suspicious activity, every member of the Emory community helps protect patients, students, colleagues and institutional information.