Table of Contents

Deepfake and AI Voice Scams: How Businesses Are Being Robbed by Voices They Trust

Picture of CyberDuo
CyberDuo

In early 2024, a finance employee at the engineering firm Arup joined a video call with his company’s CFO and several colleagues. Faces he knew, voices he knew. On that call, he was instructed to process a series of transfers, and he did, about $25 million worth. Every person on that video call except him was a deepfake.

That case made headlines because of the amount, but the technique has since gone downmarket fast. The tools that clone a voice or fabricate a video call are cheap, easy, and widely available, which means this is no longer a Fortune 500 problem. It is a Tuesday-afternoon problem for any business that moves money.

Why your ears are no longer evidence

Here is the technical reality in one sentence: a few seconds of someone’s recorded voice is now enough to produce a convincing clone that says anything. For a business owner or executive, the raw material is everywhere. A podcast appearance, a webinar, a voicemail greeting, a video on your own website, a conference talk on YouTube. If your voice exists online, it can be borrowed.

The scams built on this are upgrades of frauds you already know. The fake-CEO wire request that used to arrive as a suspicious email now arrives as a phone call in the boss’s actual voice, urgent and plausible. The vendor asking to update banking details now follows up the email with a call that sounds exactly like your longtime contact. The emotional pressure play, “I am about to board a flight, I need this handled now,” lands completely differently when it is a voice you have trusted for years.

And it works precisely because we have trained ourselves for a decade to be suspicious of email while treating a familiar voice as verification. The attackers know that. Voice is the new phishing, aimed at the one channel your team still trusts by default.

The tells (and their limits)

There are sometimes tells. Cloned voices can have slightly flat emotional range, odd pacing, or a refusal to engage in genuine back-and-forth. Deepfake video can glitch around glasses, hands, and side profiles. Asking an unexpected question (“what did we talk about at lunch last month?”) can trip a scammer who only has a script.

But be honest about the limits: the technology improves monthly, and under time pressure, on a bad phone line, with the boss’s voice telling you to hurry, most people will not catch it. Which is why the real defense is not better ears.

The defense that actually works

The fix is procedural, and it is beautifully low-tech: no voice, no video call, and no email is ever sufficient authorization to move money or change payment details. Full stop.

Practically, that means a callback rule: every wire request and every banking-detail change gets verified by calling the requester back on a number you already have on file, never a number provided in the request itself. It means dual approval on transfers above a set threshold, so no single deceived person can complete the fraud. It can even mean a shared code word for executive requests, which sounds like spy fiction and works like a charm, because a cloned voice does not know it.

Layer the technical controls behind that: hardened email security so the fraud cannot start with a compromised mailbox, multifactor authentication so accounts do not get taken over in the first place, and security awareness training that includes voice and video scams specifically, so your team’s instinct under pressure is to verify rather than comply. The whole playbook overlaps heavily with defending against classic business email compromise, because deepfakes are ultimately BEC with better production values.

One more step worth taking this week: decide with your leadership team, out loud, that anyone can pause any urgent payment request to verify it, without penalty, even if the CEO is annoyed. The scam depends on the fear of questioning authority. Kill that fear and you have killed most of the scam.

Where we come in

We build these defenses for businesses across Southern California: the verification workflows, the hardened Microsoft 365 environment, the email authentication, the awareness training that covers AI-era scams, and the 24/7 monitoring through our in-house SOC that spots account compromise before it becomes a convincing phone call. Our cybersecurity services page covers the stack, and this threat matters most for financial services firms and law firms, where a single authorized transfer can be the whole ballgame.

If your business moves money on the strength of a voice, an email, or a video call, and you have not yet built the verification layer, reach out. We work with companies across Los Angeles, Orange County, and San Diego, and this particular fix is fast, cheap, and very much worth doing before the phone rings.

Talk to our team