Your controller gets a call. It's your voice — same tone, same phrasing, same slightly rushed way you talk when you're between meetings. You need a wire sent today to close a deal. You'll explain later.
Except it wasn't you.
AI voice cloning has gone from research demo to off-the-shelf tool. A few seconds of audio — a podcast clip, a conference talk, a voicemail greeting, a LinkedIn video — can be enough to produce a convincing copy of someone's voice. Attackers are using it the same way they've always used business email compromise: to get someone to move money or hand over access.
This Isn't Hypothetical
In early 2024, a finance employee at the engineering firm Arup's Hong Kong office joined a video call with what appeared to be the company's CFO and several colleagues. Every other person on the call was a deepfake. The employee made 15 transfers totaling roughly $25 million before the fraud was discovered.
That was a large, sophisticated target. But the tools used are now cheap and widely available — and small businesses are often easier marks, because there are fewer people and fewer checks between a request and a payment.
These scams don't beat your technology. They beat your process. If a familiar voice asking for something urgent is enough to move money in your business, that's the gap they're aiming at.
What These Attacks Look Like
The urgent wire
A call or voicemail from "the owner" asking for an immediate payment to a new account, usually with a reason it can't wait.
The fake video call
A Teams or Zoom meeting where the faces and voices look right, used to approve a transfer or a change in payment details.
The help desk reset
A caller who sounds like an employee asks IT to reset a password or MFA device "because I got a new phone."
The vendor change
A familiar vendor contact calls to confirm "updated banking details" — following up on a spoofed email so it feels verified.
Why the Holidays Make It Worse
The end of the year is peak season for payment fraud. More invoices are moving, year-end deals are closing, people are out of the office, and everyone is in a hurry. That's exactly the environment where "just send it, I'll explain later" gets through.
Five Rules That Stop It
You can't train people to reliably tell a good deepfake from the real thing. You can make it not matter.
Verify through a second channel — always
Any request to move money or change payment details gets confirmed by calling the person back at a number you already have on file. Never the number in the email, the text, or the caller ID.
Two people for every wire
No single person can both request and release a payment. A deepfake has to fool two people through two channels — much harder.
Agree on a verification phrase
Leadership and finance share a code word that never appears in email or chat. If the "CEO" on the phone doesn't know it, the request stops.
Lock down help desk resets
Password and MFA resets require identity verification beyond a voice — a callback, a manager's approval, or an in-person check. This is the attack path most small businesses overlook.
Make "slow down" safe to say
Urgency is the attacker's main tool. Tell your team in writing that no one will be penalized for pausing a payment to verify it — including when the request comes from you.
Train for It Like Phishing
Security awareness training has mostly focused on email. It now needs to cover voice and video. The best programs include short, practical examples of AI impersonation and walk people through exactly what to do when a request feels off.
October is Cybersecurity Awareness Month. If your team hasn't talked about deepfake scams yet, this is a good week to do it — before the year-end payment rush starts.
Free Payment Fraud Readiness Check
We'll review how money and access requests actually get approved in your business and show you where an impersonation attempt would get through.
DM us "ASSESS" on LinkedIn or schedule a free consultation · (646) 791-2137