CyberPlay editorial team · Published · Updated · 8 min read
Guide and exercises in English

Expand image · Course video frame · English interface
Deepfake voice fraud training should teach one repeatable decision: pause a request for money or account access, end the incoming conversation and verify through an established contact route. Recognising a voice or face is not enough to authorise a payment, reset an account or share a code. The useful skill is knowing how to check when the person sounds entirely convincing.
CyberPlay Courses introduces that decision through short video lessons with answer checkpoints. This guide connects the voice, phone-scam and payment lessons with The Social Engineer, then adds a workplace exercise. Course narration is available in English and Romanian; the platform and this game support all nine site languages.
What you’ll take away
- A familiar voice can support a story without proving who controls the call.
- A callback uses contact details established before the suspicious request.
- Confirming identity does not replace payment approval or account-recovery checks.
- Courses explain the decision; game practice and a new scenario reveal what needs discussion.
2. Start with what the caller wants you to change
Use the fictional prompts below to build a role-specific discussion. Ask learners to name the requested action before debating whether the voice sounds artificial. A person may have a reasonable explanation for poor audio or an unfamiliar number. That explanation does not settle whether the requested action is authorised.
| Fictional request | Decision at risk | Safe next step |
|---|---|---|
| Your director asks for a confidential transfer before a meeting. | Payment and approval controls. | Hold the request and contact the director through the established directory. |
| A colleague says a lost phone requires an urgent MFA reset. | Account recovery and enrolment of a new factor. | Apply the approved identity-verification and recovery procedure. |
| A support caller asks for a code to stop an attack. | Authentication or device access. | Do not disclose the code; contact the known service desk. |
| A familiar supplier voice confirms new payment details. | A change to the payee record. | Use the existing supplier contact and the payment-change process. |
3. Rehearse an independent callback
The FTC's voice-cloning guidance recommends contacting the person using a number already known to be theirs. Apply that principle at work with the approved directory or an established supplier record. Redialling the incoming number, following a new chat invitation or using a number supplied in the request keeps the check inside the caller's story.
Practise a short response: “I will check through our normal contact route and follow the approval process.” Then end the call. For this exercise, ask the learner to point to where they would obtain the trusted contact. If that route is unavailable, identify the designated escalation contact and keep the requested action on hold. A deadline is a reason to escalate the delay, not to invent a substitute verification method.

Expand image · Course video frame · English interface
- Leave the incoming call
End the conversation before verifying through a number already saved for the person.
- Verify the request, not the voice
Urgent money and secrecy are reasons to use the established process, even when the voice sounds familiar.
Section sources: Scammers use AI to enhance their family emergency schemes
4. Keep payment approval separate from recognising the person
A successful identity check answers who you reached. The organisation's payment process answers whether the transfer, recipient and amount are approved. In a training discussion, keep those questions separate. Even an authentic manager can ask for something outside their approval authority or overlook a changed supplier record.
Give the finance team a fictional request with a correct project name, a realistic invoice and a familiar voice message. Ask them to locate the approved payee record, explain the required independent verification and identify who must authorise the payment. The aim is a usable sequence, including what happens when an approver is absent. IC3 recommends a secondary channel for account-information changes; your team must map that advice to its actual controls.
Section sources: Business Email Compromise: The $55 Billion Scam
5. Include the service desk in the same lesson
The July 2025 joint Scattered Spider advisory describes criminals impersonating employees to persuade helpdesks to reset passwords or transfer MFA to attacker-controlled devices. It also describes callers pretending to be support staff. The advisory does not establish that every such call uses a deepfake; ordinary persuasive conversation is enough to make recovery procedures worth rehearsing.
Run the scenario from both sides. An employee must know where to report an unexpected support call. A helpdesk worker must know the approved identity check, when to escalate and how to handle a caller who cannot use their usual factor. Do not turn knowledge of a job title, manager or current project into an improvised identity test. Record any missing recovery route as a process gap for its owner.
Section sources: Scattered Spider: joint cybersecurity advisory, July 2025 update
6. Use three Courses to build the decision in stages
Begin with A copied voice, a copied face for the problem of trusting familiar audio or video. Follow with Vishing: convincing phone scams to practise ending a call and using a contact you independently locate. Add Call before you pay for finance staff, managers and anyone handling payment requests. These are three different angles on the same verification habit.
Each CyberPlay course has five checkpoints where the video stops for an answer before the explanation. Ask learners to explain a missed decision in their own words. A correct checkpoint answer is evidence about that exercise; it does not establish that a real transfer would be stopped. The selected lessons offer English or Romanian narration. Their availability depends on the learner's account and plan.
- Course: A copied voice, a copied face
- Course: Vishing: convincing phone scams
- Course: Call before you pay

Expand image · Course video frame · English interface
- Use a contact from before the request
Find the number in a trusted existing record rather than in the message being checked.
- Keep the second approval
A convincing call or video does not replace the separate approval required by your payment process.
7. Transfer the habit to The Social Engineer
The Social Engineer includes an incoming “IT Security” call that pressures the player to install a support tool. The player can contact the published helpdesk and report the attempt. Another scenario presents an urgent, confidential executive payment request and offers verification through a separate known channel. These are actual scripted decisions in the game, with fictional organisations and contacts.
Use the game after the relevant Courses and ask what changed when the request appeared in a busy working day. The game rehearses verification under pressure; it is not a detector test for synthetic voices or a live audit of your helpdesk. Review the decision and its debrief, then ask the learner to identify the equivalent contact route at work.
8. Try a fresh scenario without judging the voice
Read this invented case aloud or use ordinary text. No cloned colleague voice, real bank details or surprise call is needed. The exercise tests the response to a request, so a facilitator can vary the urgency while keeping the decision clear.
9. Make the next action easy to find
If money has already moved, notify the designated finance and security contacts immediately so the financial institution can be contacted about a recall. IC3 emphasises prompt contact with the financial institution; recovery is not guaranteed. If an account change, code disclosure or remote-access action occurred, tell the response team exactly what happened and when, then follow its instructions. Preserve the original messages through the approved reporting route.
End the session with a small deliverable: a verified contact route, an escalation owner and a clear payment or recovery procedure. Repeat a changed fictional scenario later and discuss the explanation, not just the score. If learners know the safe answer but cannot find the approved contact, the next improvement belongs in the workflow as well as the training.
Section sources: Business Email Compromise: The $55 Billion Scam
Practise the callback decision in English
Follow the voice and payment Courses with The Social Engineer. Rehearse a known-channel check, explain your decision and read the scenario debrief.
Play The Social EngineerSources and further reading
- Senior U.S. Officials Continue to be Impersonated in Malicious Messaging Campaign — FBI Internet Crime Complaint Center. Accessed 2026-10-03
- Protecting organizations from AI-assisted executive impersonation and invoice fraud — Microsoft Security. Accessed 2026-10-03
- Scammers use AI to enhance their family emergency schemes — Federal Trade Commission. Accessed 2026-10-03
- Scattered Spider: joint cybersecurity advisory, July 2025 update — FBI, CISA and international partner agencies. Accessed 2026-10-03
- Business Email Compromise: The $55 Billion Scam — FBI Internet Crime Complaint Center. Accessed 2026-10-03
Keep exploring
- Social engineering training exercises: rehearse impersonation and payment checks
Run practical social engineering exercises for fake IT support, supplier payment changes and voice impersonation, with dialogue cards, verification steps and debriefs.
EN · 8 min read - Invoice fraud: how to verify a supplier’s bank-account change
Prevent invoice fraud with an independent supplier callback, bank-detail comparison and approval record. Includes a practical finance worksheet and game exercise.
EN · 8 min read - Unexpected MFA request? What to do when you did not sign in
Received an MFA prompt you did not initiate? Learn when to deny it, verify a support call, report an accidental approval and practise the decision in English.
EN · 8 min read - Prompt injection training for employees: check what your AI assistant can do
Teach employees to check AI actions, protect work data and report mistakes. Pair CyberPlay Courses with Data Dash practice and a practical approval checklist.
EN · 8 min read - Session and device-code phishing: why a real login page is not enough
Compare session-cookie theft, device-code phishing and OAuth consent. Learn the safe employee action with CyberPlay Courses and Find the Fake Login.
EN · 8 min read - Is public Wi-Fi safe for work? Hotspots, HTTPS and fake portals
Learn when public Wi-Fi is suitable for work, how to verify hotel hotspots, spot fake login portals and certificate warnings, and choose an approved connection.
EN · 8 min read