Field Guide to AI, Security and Cybercrime

Someone Made a Deepfake of You: What to Do First

The first hours decide whether a fake video or cloned voice stays contained or spreads. Most of the right moves are dull, and they work.

Field Guide to AI, Security and Cybercrime·Abdolmadjid Masoomi·4 October 2026·6 min read

When a deepfake shows you saying or doing something you did not, your first moves decide the outcome. Preserve evidence before anything is taken down, report through impersonation and synthetic-media channels, warn the people most likely to be targeted, and get legal advice when the fake is defamatory or extortionate.

The fake is the first problem. Your reaction is the second.

You assume a deepfake is a contest with a clever piece of software. In practice it is a contest of attention, and the first hours decide most of it. The instinctive responses all make things worse in their own way: a furious public denial carries the fake to people who had not seen it, a hurried report under the wrong category gets dismissed by an automated queue, and waiting for it to blow over lets the story set.

This piece covers fakes that put words or actions in your mouth: a video of you endorsing a product you have never used, a clip of a confession that never happened, a cloned voice calling your contacts. Sexual deepfakes are a different and more urgent case with faster removal routes, set out in getting an intimate deepfake removed; if that is what you are facing, start there.

Your aim in the first hours is not to erase the fake from the internet. That is rarely possible. It is to stop it reaching the people whose opinion of you matters, and to build a record that will hold up later.

Preserve the evidence before anything is taken down

Do this first, before you report, before you post, before you ask anyone to delete anything. Platforms can remove content quickly once a report lands, and without a record you have nothing to show a platform appeal, a lawyer or the police.

Make one folder and put everything in it:

  • The address of every place the fake appears, copied as text.
  • Screenshots that show the address bar, the content, the account that posted it, and the visible date and time.
  • The file itself, if you can save it without installing anything unfamiliar.
  • A short log: where you found it, who told you, when, and what you did.

Keep the folder somewhere other than the device you use for everything else, and write the log as you go rather than reconstructing it later. A case that is documented on day one is a different thing from a grievance described from memory.

Report it through the channel built for it

Reporting the post as spam or as "offensive" usually fails. Use the routes platforms have for exactly this:

  • Impersonation, when an account is pretending to be you.
  • Manipulated or synthetic media, for the specific post or video, stating that it is a fabricated likeness of you.
  • The hosting provider, when the fake sits on an independent website. The site owner may be the problem; the company hosting the site usually has terms the fake breaks.

Keep the report short and factual: who you are, that the content is a fabricated likeness, what it falsely shows, and that you did not consent. Attach the evidence. If the first answer is a rejection, appeal once with the same facts, and note the reference number in your log.

Tell the people who matter before they hear it elsewhere

Hold back on the public statement. Your first messages should be private and targeted: your employer or manager, close family, important clients and colleagues, anyone the fake is designed to influence.

The message can be three sentences. A fake video or audio clip of you is circulating. It is fabricated. You are dealing with it through the proper channels, and you would be grateful if they did not share it.

This does two things. It protects the relationships the fake was aimed at, because people who hear about it from you first rarely believe it later. And it turns those people into allies who will quietly correct others instead of forwarding the clip.

A public statement may still be needed, especially if the fake is spreading or you have a public role. When you make it, make it once, on your own channels, and do not argue under the fake itself. Replies under the original post are engagement, and engagement is what spreads it.

The cloned-voice variant

A cloned voice is often used not to embarrass you but to defraud the people who know your voice: a call to a parent asking for money, a message to a colleague approving a payment.

If you learn that a clone of your voice is in use, warn the people most likely to be called: family, your finance team, anyone who acts on your instructions. Agree a simple rule that a request for money or access is always confirmed through a second channel you already use. For family, a pre-agreed phrase works well, and a family safe word explains how to set one up so that it actually gets used under pressure.

When it is an attack, bring in the law

Some fakes are not just misleading. If the fake damages your reputation with false statements of fact, is being used to demand money, is part of a fraud against others, threatens you, or involves a child, escalate.

The law that may apply depends on the country, and can include defamation, harassment, impersonation and fraud, and data-protection rules on the use of your likeness. A lawyer who handles online harms can ask platforms to preserve data and can approach the person responsible. Threats, extortion and fraud should go to the police, with your evidence folder. Where consent to use your face or voice is the issue, the principles in consent for digital replicas are a useful frame for what you can reasonably ask for.

Questions people ask

Should I reply under the post to say it is fake?

Usually not. Replies count as engagement and can push the post to more people, and your denial ends up pinned under the fake. Correct the record on your own channels, after you have warned the people who matter.

Can I find out who made it?

Rarely by yourself. Platforms may hold the information but generally disclose it only through a legal process, which is one reason legal advice matters in serious cases. Your time is better spent on evidence, reporting and containment.

Will content credentials or watermarks stop this?

They help prove that genuine material is genuine, which is valuable, but they do not stop someone creating a fake from scratch. What content credentials prove is real but narrow: provenance for authentic files, not a ban on fabricated ones.

Is it illegal for someone to make a deepfake of me?

It depends on the country and on the use. Parody and commentary can be protected in some places. Using your likeness to deceive, defame, harass, extort or commit fraud is unlawful in many jurisdictions, and platforms generally prohibit deceptive synthetic impersonation whatever the local law says.

Close

A deepfake attacks your identity, and the counter-attack is procedural. Folder, screenshots, the right report form, three private messages, and a lawyer when the fake becomes a weapon. None of it is dramatic, and that is why it works: you stop reacting to the content and start managing the incident, which is the only part of this you control.

Questions people ask

Should I reply under the post to say it is fake?

Usually not. Replies count as engagement and can push the post to more people, and your denial ends up pinned under the fake. Correct the record on your own channels, after you have warned the people who matter.

Can I find out who made it?

Rarely by yourself. Platforms may hold the information but generally disclose it only through a legal process, which is one reason legal advice matters in serious cases. Your time is better spent on evidence, reporting and containment.

Will content credentials or watermarks stop this?

They help prove that genuine material is genuine, which is valuable, but they do not stop someone creating a fake from scratch. What content credentials prove is real but narrow: provenance for authentic files, not a ban on fabricated ones.

Is it illegal for someone to make a deepfake of me?

It depends on the country and on the use. Parody and commentary can be protected in some places. Using your likeness to deceive, defame, harass, extort or commit fraud is unlawful in many jurisdictions, and platforms generally prohibit deceptive synthetic impersonation whatever the local law says.

Ask NEXUS about this article

Get an AI-powered summary, key points, or follow-up questions about Someone Made a Deepfake of You: What to Do First, grounded in the essay content and the broader corpus.