Local Business

AI voice cloning and payment fraud: the controls that stop a fake CEO call

Business email compromise has learned to talk. Cloned voices and deepfake video now back up fraudulent payment requests. Here is how the scam works and the finance controls, callback rules, and staff habits that stop it.

September 25, 2026 7 min read securityfraudAIsmall businessfinance

Your office manager gets a call late on a Friday. It is the owner’s voice, slightly rushed, calling from what sounds like an airport. A supplier deal is about to fall through, the wire has to go out today, the details are in an email that just arrived. The voice sounds right. The urgency sounds right. The email looks right. The money goes.

For years, this scam arrived by email alone. It is called business email compromise, and it has cost businesses of every size a great deal of money. What has changed is that the email now has backup. Tools that clone a voice from a short recording are widely available, and a few minutes of someone speaking on a podcast, a webinar, a voicemail greeting, or a social video can be enough raw material. Deepfake video on a call is harder to pull off convincingly, but it is getting easier.

The answer is not to become an expert at spotting fakes. The fakes will keep improving. The answer is to build payment processes that do not depend on recognizing anyone’s voice or face.

How the scam usually works

The pattern is consistent, whether the channel is email, phone, text, or video.

Research. The attacker learns who approves payments, who the regular suppliers are, and who the owner or finance lead is. Much of this is public: your website, LinkedIn, news coverage, the “our team” page.

Access or impersonation. Sometimes they break into a real mailbox, often through a phishing page and an account without multi-factor authentication, and read weeks of genuine invoices and conversations. Other times they register a lookalike domain one letter off from yours or a supplier’s.

The request. A change of banking details for a known supplier, or an urgent one-off payment from a senior person. The request is timed for pressure: end of day, end of week, the boss travelling and hard to reach.

The reinforcement. This is the new part. A voice call or voicemail in a familiar voice confirms the email. The target, who might have questioned an email alone, is reassured by hearing someone they know.

Every step relies on the same thing: that the person moving the money will trust the channel the request arrived on. Break that assumption and the scam fails.

The core rule: verify out of band

Out-of-band verification means confirming a request through a separate channel that the requester did not supply. It is the single most effective control against this whole category of fraud.

If a request arrives by email, you verify by phone, using a number you already had on file. Not the number in the email signature. Not the number the caller gives you. If a request arrives by phone, you verify by calling back on the known number, or by walking down the hall.

A cloned voice cannot answer a call placed to the real person’s real phone. That is why the callback works, and why it must go to a number from your own records.

Payment-change procedures

Changes to supplier banking details are the most common target, because a single successful change can redirect every future payment. Write down a procedure and follow it every time, even for suppliers you have worked with for years.

  • Never accept a banking change by email alone. Treat every change request as unverified until confirmed.
  • Call the supplier on a number from your records. Use the phone number from your original onboarding, a past invoice you trust, or their public website. Ask for someone you already deal with.
  • Confirm the details verbally. Read back the new account details, or have them read theirs to you, and compare.
  • Require a second person to approve the change. Whoever enters new banking details should not be the only person who signs off on them.
  • Watch the first payment. After a change, consider a small test payment and confirm receipt with the supplier before sending the full amount.
  • Log it. Record who requested the change, who verified it, how, and when.

Code words and challenge questions

For requests from inside the business, particularly from owners and senior staff, a simple verbal code can help. Agree on a word or phrase, shared in person, never written in email or chat. Anyone making an unusual payment request by phone or video must be able to say it.

Code words are a useful backstop, not a replacement for callbacks. They can leak, and people forget them. Change the word periodically and after anyone who knew it leaves. A reasonable alternative is a challenge question with an answer only the real person would know and that is not findable online.

The most important part is cultural: senior people must expect to be challenged and must never punish someone for checking. An owner who snaps “just send it” at a staff member asking for a callback has just trained the team to skip the control that protects the business.

Finance controls that do not depend on judgement

Callbacks rely on people remembering to make them under pressure. Structural controls make the right behaviour the only available path.

  • Dual approval above a threshold. Pick an amount that makes sense for your business. Above it, two people approve every payment, and one of them verifies the payee.
  • Separate duties. The person who adds or changes a payee should not be the same person who releases payments to that payee.
  • Use your bank’s controls. Many business banking platforms support multiple approvers, payee whitelisting, and alerts on new payees. Ask your bank what they offer and turn it on.
  • No exceptions for urgency. Write it into the procedure that urgency is not a reason to skip verification. Urgency is a warning sign.
  • Protect the mailboxes. Multi-factor authentication on every email account, especially finance and leadership. Email authentication records (SPF, DKIM, and DMARC) make it harder for anyone to send mail that appears to come from your domain.

Training that actually sticks

Annual slide decks do not change behaviour much. Short, specific, repeated conversations do.

Walk your finance and admin staff through the scenario at the top of this post. Ask them what they would do. Then make sure they know three things: they are allowed to slow down any payment, they are expected to call back on a known number, and nobody will be annoyed with them for doing it.

It also helps to reduce the raw material. Consider how much of your senior team’s voice is publicly available, and whether voicemail greetings need to be in a personal voice at all. You will not eliminate exposure, but you do not need to make it easy.

A one-page checklist for this month

  • Multi-factor authentication on every mailbox, starting with finance and leadership
  • Written procedure for supplier banking changes, with callback to a known number
  • Dual approval for payments above a set threshold
  • Bank-level controls reviewed and enabled
  • Internal code word or challenge question agreed in person
  • Fifteen-minute team conversation about the scenario, and explicit permission to slow down
  • SPF, DKIM, and DMARC checked on your domain

Where this fits

Most of these controls are process, not technology, and they cost very little. The technology underneath matters too: multi-factor authentication stops the mailbox takeovers that make these scams convincing, and email authentication makes your domain harder to impersonate. If you want someone to look at the whole picture, our cybersecurity service covers these controls as part of ongoing work.

Send us a short brief about how payments are approved in your business today, and we will reply in writing within one business day.

— Newsletter

Get the writing by email.

An occasional note from the team — case studies, new free tools, engineering essays. Never daily.

Three fields, no tracking. Privacy policy.

Esc