For those working in cyber security, there is a feeling that has now become a daily reality. Firewalls, EDRs and network segmentation remain essential, of course. But the most dangerous front is no longer the technological one. It is the cognitive one. That is where the most complex battle is now being fought against manipulation, deception and the distortion of reality.
We live immersed in a seemingly endless flow of information. Yet, paradoxically, the truth is becoming increasingly difficult to discern. This is because attackers no longer confine themselves to sending grammatically incorrect emails or suspicious links. They now construct narratives, voices, faces and contexts that appear authentic in every respect. Disinformation no longer has the feel of a naive hoax. It has the air of professionalism.
From old-school fake news to synthetic content
Once upon a time, fake news was mostly clickbait stories. Today, it has become perfectly crafted content, designed to mimic official reports, authoritative newspapers or internal company communications.
The difference lies in the quality. Generative models are capable of replicating a person’s style, the way they write, and their characteristic turns of phrase. It is the same evolutionary leap that took us from amateur photo editing to professional deepfakes. It is no longer a matter of ‘false content’. It is a matter of ‘credible content’. And that is a huge difference.
Deepfakes and voice cloning: when it’s no longer you speaking
The real paradigm shift comes with synthetic media. You watch a video and it looks as though you’re seeing a colleague or a company executive. The voice is perfect, as are the facial movements. The request is urgent and plausible. Everything adds up. But it doesn’t.
The same applies to voice cloning. We’re not talking about a rudimentary imitation, but the reproduction of pauses, expressions and intonations. An untrained ear cannot tell the difference. And indeed, attackers are well aware of this. All it takes is a voice message forwarded in a WhatsApp group to trick someone into taking impulsive action.
And the more accessible these techniques become, the more deeply they become embedded in everyday life. No laboratory-level expertise is required. All it takes is intent.
Where criminals operate: email, chat, the web
The creativity of an attack is worthless without an effective delivery vector. And criminals go where we all are.
Email remains the most exploited entry point, except that it no longer contains glaring errors. They are clean, coherent and tailored to the recipient. In chat platforms, the potential is enormous. A voice message that appears to come from a family member can trigger an immediate reaction. And on the web, finally, sites imitating newspapers and blogs are proliferating, with a single mission: to manipulate public opinion or spread malware under false pretences.
Essentially, synthetic disinformation has grasped one simple thing. People do not verify abstract content. They verify experiences. And when these experiences seem real, their critical filter breaks down.
How to defend yourself: verification as a technical skill
In everyday practice, defending yourself against all this means adopting a method. A form of technical scepticism. We can no longer take anything that passes before our eyes at face value.
First of all, the source. Where does a news item come from? An email? A video? If we cannot trace it back to its source, we must stop. Then comes cross-checking. Is anyone else, acting independently, reporting the same information? And finally, there is the verification of the content itself, especially when it comes to the media. Analysing metadata, using deepfake detection tools, examining frames, inconsistencies and micro-errors. It is work that requires attention. But today, this is the norm.
And there’s one point that’s often underestimated: the responsibility of sharing. Every time we forward something without verifying it, we amplify the problem. We become part of the attack vector. And in 2026, we can no longer afford to do that.
Let’s clarify
What is voice cloning and why is it so dangerous?
It’s a technology that recreates a person’s voice down to its most distinctive details. It’s dangerous because it allows people to impersonate trusted figures and obtain actions or information that would never be granted to a stranger.
How can I tell if a text has been generated by AI?
It generally lacks real-world references, verifiable context, and consistency with facts and reliable sources. The advice is always the same: don’t stop at the first piece of content you see; look for confirmation on independent channels.
What should I do if I receive a suspicious video?
Don’t be swayed by the visual impact. Check the source, look for the same information elsewhere and, if possible, analyse the file using tools designed to detect manipulation.
In conclusion
Cybersecurity today hinges on the ability to distinguish between what is true and what is designed to appear true. And this is a skill that cannot be left to technology alone. It requires method, clear thinking, and the realisation that the content we consume is no longer neutral. It is a battlefield.
In a world where everything can be faked, the truth is not found by chance. It must be sought out carefully.
By Ugo Vergallo – Lead Cybersecurity Architect, Cyberoo