Deepfake Calls and AI Voice Cloning: The Scam Your Finance Team Will Face in 2026
A few seconds of audio from a podcast, voicemail greeting, or social video is enough to clone a voice convincingly. AI-powered impersonation has moved from research labs into everyday fraud playbooks — and small businesses are now the preferred target. Here is how these attacks actually unfold, and the zero-cost verification procedures that defeat them.
Key Takeaways
- Voice cloning needs only a few seconds of audio — a podcast clip, webinar, or voicemail greeting is plenty
- Attackers have faked entire video conferences; one finance employee was tricked into wiring roughly $25 million after a deepfaked call with what looked like the CFO
- The FBI reports business email compromise losses near $2.8 billion per year, and AI is making the lures dramatically more convincing
- Urgency, secrecy, and new payment details are the red flags that survive even a perfect voice
- Callback verification on a known-good number costs nothing and defeats nearly every impersonation attack
The $25 Million Video Call
In early 2024, a finance employee at the engineering firm Arup joined a video conference with the company's CFO and several colleagues. Faces looked right. Voices sounded right. By the end of the call, the employee had authorized transfers totaling roughly $25 million.
Every other person on that call was a deepfake.
That case made headlines because of the amount. What should worry small business owners is the trajectory: the tools that produced that call have only become cheaper, faster, and easier to use since. What once required a well-funded criminal operation now runs on consumer hardware with off-the-shelf software.
Why Small Businesses Are Now the Preferred Target
Large enterprises have spent years hardening their payment workflows. Many small businesses have not — and attackers know it. Three things make smaller companies attractive:
- Informal approval chains. When the "CEO" calls and says wire the deposit today, there is often no written procedure that says otherwise.
- Public audio everywhere. Owners and managers appear on podcasts, local news, webinars, and social videos. A few seconds is enough source material for a convincing clone.
- One person holding the keys. In many small firms a single bookkeeper or office manager can move money alone — exactly the person these scripts target.
The FBI has warned that criminals are using generative AI to scale these schemes, and its latest figures put business email compromise losses near $2.8 billion a year — a category that increasingly blends email with cloned phone calls to "confirm" the fraudulent request.
How the Attack Actually Unfolds
These are not random robocalls. A typical AI-assisted impersonation campaign runs in four stages:
- Reconnaissance. The attacker maps your company from LinkedIn, your website, and public filings: who approves payments, who their boss is, which vendors you use.
- Harvesting. They collect voice samples from podcasts, conference talks, social clips — even an outgoing voicemail greeting.
- The pretext. A believable scenario: a confidential acquisition, an urgent vendor payment, a payroll banking change, or a "locked-out executive" calling the help desk for an MFA reset. That last one is how attackers breached MGM Resorts in 2023 — by phoning the service desk.
- Pressure. Whatever the script, it always combines urgency ("this must happen before close of business") with secrecy ("the deal is confidential — don't loop anyone in").
Red Flags That Survive Even a Perfect Voice
You cannot reliably "hear" a deepfake anymore. But the structure of the scam cannot hide:
- Urgency plus secrecy. Legitimate transactions almost never require both speed and silence.
- New payment details. Any change to a bank account, wire destination, or payroll deposit is the single highest-risk event in your finance workflow.
- Channel switching. An email that says "I'll call you to confirm," followed by a call that references the email, feels like double confirmation — it is actually one attacker using two channels.
- Resistance to callbacks. Anyone who objects to "let me call you back at the number we have on file" has told you everything you need to know.
The Defense That Costs Nothing: Verification Procedures
The strongest countermeasures here are written procedures, consistently applied:
- Callback verification. Every payment request, banking change, or sensitive data request gets verified by calling the requester back on a number from your records — never one provided in the request itself.
- Dual approval. No single person can initiate and approve a transfer above a threshold you set. Two people, two channels.
- Verification phrases. Agree on a private phrase leadership uses to authenticate unusual requests. It never appears in writing.
- Help desk identity checks. Password and MFA resets require verification that a cloned voice cannot supply — not "sounds like the boss."
- A no-penalty pause rule. Make it explicit that no employee will ever be disciplined for delaying a payment to verify it. Pressure only works when people fear saying "let me check."
Harden the Technical Side Too
Procedures carry the load, but technology narrows the attack surface:
- Phishing-resistant MFA (hardware keys or passkeys) on email, banking, and payroll systems — cloned voices cannot phish what users cannot type.
- Email authentication (SPF, DKIM, DMARC) so spoofed "confirmation" emails are rejected before they land. Our email security assessment checks this in minutes.
- Audit public audio. Know what recordings of your leadership exist publicly. You will not remove them all — but knowing your exposure informs your verification phrase policy.
- 24/7 monitoring. Impersonation is usually one stage of a longer intrusion. Detection that watches around the clock catches the stages before and after the phone call.
Train Like It's Real
Annual slide decks do not prepare a bookkeeper for a caller with the boss's voice. Effective programs use realistic simulations — phishing emails and voice pretexts that mirror current criminal scripts — followed by short, blameless coaching. Teams that have rehearsed the "let me call you back" reflex use it under pressure. Teams that have only read about it freeze.
Want a second set of eyes on your payment verification process? We help small businesses put these procedures in place and pressure-test them with live simulations. Reach out through our contact form or call (818) 574-8240 for a free consultation.
Wisetechy Solutions
Wisetechy Solutions is a founder-led IT and cybersecurity provider for small businesses, founded and run by a CISSP-certified security professional with hands-on IT experience dating back to 1995.
Explore More Resources
Related Articles
Cyber Insurance: The Safety Net Your Small Business Can't Afford to Skip (Literally)
Why cyber insurance isn't just another expense—it's the difference between a costly mistake and closing your doors forever. Plus, the secret weapon most small businesses are missing.
Why 95% of Cyberattacks Start With Your Employees (And What to Do About It)
Your biggest security vulnerability isn't your firewall or antivirus—it's the person sitting at the desk. Here's how to turn your team from a liability into your best defense.
Ransomware: Why Small Businesses Are Prime Targets (And Your 3-Step Defense Plan)
82% of ransomware attacks hit small businesses. Here's why hackers love you more than Fortune 500 companies—and the surprisingly simple steps that make you a harder target.