Episode

Stop Deepfake BEC: The Verified ID Strategy

Podcast
M365.FM - Modern work, security, and productivity with Microsoft 365
Published
May 5, 2026
Duration seconds
1253
Processing state
not_requested
Canonical source
https://www.spreaker.com/episode/stop-deepfake-bec-the-verified-id-strategy--71870989
Audio
https://dts.podtrac.com/redirect.mp3/api.spreaker.com/download/episode/71870989/stop_deepfake_bec_the_verified_id_strategy.mp3
JSON
/v1/public/podcasts/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214/episodes/stop-deepfake-bec-the-verified-id-strategy
Markdown
/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214/stop-deepfake-bec-the-verified-id-strategy.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214/episodes/stop-deepfake-bec-the-verified-id-strategy/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/m365-fm-modern-work-security-and-productivity-with-microsoft-365-7311214/stop-deepfake-bec-the-verified-id-strategy.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

A wire request lands in your inbox. Everything looks right—the name, the tone, even a voice note that sounds exactly like your CEO. In the past, that was enough. Today, it’s a liability. This episode breaks down a hard truth: trust based on recognition is no longer safe. We’re no longer dealing with crude phishing attempts—we’re facing believable authority powered by AI. Traditional controls like SPF, DKIM, and DMARC still matter, but they only validate the path of a message, not the person behind it. And that gap is exactly where deepfake Business Email Compromise thrives. If your organization still trusts email signals to authorize high-risk actions, you’re already exposed. THE EMAIL HEADER IS NO LONGER A TRUST SIGNAL For years, we relied on familiar cues—display names, domains, writing styles—to make quick trust decisions. But AI has erased the old tells. Attackers can now generate flawless messages, mimic executive tone, and align perfectly with real business context. Emails don’t need to look suspicious anymore—they just need to feel familiar for a moment. And sometimes, they’re not even spoofed. They come from real accounts, through trusted SaaS platforms, passing every technical check. That’s the dangerous shift: your security stack sees a valid message, your team sees a believable request—but neither answers the only question that matters—should this action be allowed? WHAT EMAIL SECURITY PROVES—AND WHAT IT NEVER COULD Mail authentication validates infrastructure, not intent. SPF confirms sending servers, DKIM ensures message integrity, and DMARC aligns policies—but none of them verify human authority. A perfectly authenticated email can still carry a fraudulent request. That’s not a failure of the tools—it’s a misuse of them. We’ve been asking email security t…