Deepfake attacks on Manufacturing Supply Chains

New research from CYFIRMA warned that deepfake technology has evolved from a reputational and disinformation concern into a... The post Deepfake attacks emerge as growing operational and financial threat to manufacturing supply chains, CYFIRMA warns appeared first on Industrial Cyber.

New research from CYFIRMA warned that deepfake technology has evolved from a reputational and disinformation concern into a material operational and financial risk for manufacturing supply chains. Recognizing that manufacturers face particular exposure because of distributed, multi-tier vendor networks, high-value payments, hybrid IT-OT environments and widespread reliance on voice and video communications among procurement, finance and engineering teams. Attackers can use synthetic audio and video to impersonate executives or suppliers, potentially redirect shipments, alter payment details or pressure employees into bypassing established controls.

The report also highlighted growing risk of synthetic identities being used to infiltrate manufacturing workforces, including through remote hiring processes. 

CYFIRMA said North Korean-linked IT worker campaigns have targeted critical manufacturing and other sectors, with researchers observing a shift from static images to real-time deepfake video during job interviews. The firm said no single technology, including provenance standards, watermarking or AI detection tools, can currently close the gap on its own. Instead, manufacturers should rely on independent out-of-band verification, stronger payment and vendor-change controls, deepfake-aware hiring practices and greater scrutiny of high-stakes requests across procurement, finance and human resources. 

This comes as the firm surveys four converging attack patterns-executive/vendor impersonation fraud, synthetic identity infiltration of the workforce, supply-chain-level disinformation and reconnaissance, and emerging risks to physical quality/provenance processes-and maps them to the manufacturing threat surface specifically. It also observes a defense framework organized around identity verification, payment-process hardening, workforce screening, and content provenance, referencing current U.S. government guidance and industry standards.

According to public reporting, global engineering firm Arup lost $25 million in January 2024 after attackers used AI-generated video and audio to impersonate senior executives during a live video call and persuade an employee to authorize the transfer. Fraud-detection firm Pindrop later reported a 1,210% increase in AI-driven fraud attacks during 2025, with figures supplied to trade press estimating $1 billion in combined losses among more than 50 major U.S. customers. 

Meanwhile, North Korean state-linked operatives have expanded fraudulent remote-worker infiltration schemes beyond technology, critical manufacturing and transportation. A May 2024 U.S. Department of Justice case involving an Arizona ‘laptop farm’ found that the scheme had infiltrated more than 300 U.S. companies, including an aerospace manufacturer.

As of mid-2026, security researchers assess that North Korean IT-worker operations are using real-time deepfake video during live hiring interviews, potentially defeating conventional liveness detection. A joint alert from 11 nations in July 2026 warned of hiring-interview video feeds that appeared manipulated or artificially generated. 

The threat is difficult to address with a single technical control. Microsoft Research said in February that no foolproof method exists for media integrity and authentication, while the European Union’s March 2026 draft Code of Practice similarly proposed layered approaches to marking and labeling AI-generated content rather than relying on one mechanism.

Manufacturing has become a disproportionately attractive target for deepfake-based fraud due to its operational structure. The sector combines high-value, time-pressured payments to unfamiliar o

Source: Industrial Cyber