The control that most businesses depend on to stop a fraudulent payment is this: if a request looks unusual, someone picks up the phone and checks with the person who asked. Recognising the voice is the verification.
That control is gone. Not weakening, gone. Cloning a voice convincingly now requires a short sample of public audio, and video is following the same curve. Meanwhile the surrounding pretext has got much better too, because the badly worded email that used to give a scam away is now written fluently in your company's tone, from a real thread the attacker has read.
The reassuring part is that almost none of this is technically novel. It is invoice fraud, payroll diversion and business email compromise, which are decades old, with a new front end. The countermeasures are correspondingly old, and they are process controls rather than products.
The short version
- Voice and video are no longer proof of identity. Any control whose final step is "I recognised them" has failed and needs replacing now.
- The attack is nearly always a payment change: new bank details on an invoice, an urgent transfer, a payroll destination update. Defend the payment, not the perception.
- Callback on a number you already hold is the single highest-value control, and it costs nothing.
- Urgency plus secrecy is the actual signature, not a technical artefact. Train people to notice the pressure, not to spot a fake.
- The finance team needs explicit permission to slow down. Most successful frauds succeed because someone was afraid of annoying a senior person.
What these attacks actually look like
Three shapes cover most of what we see.
The executive request. A call or video call, apparently from a director or the owner, about a confidential and time-critical payment. Sometimes a meeting with more than one familiar face. The pressure is always the same combination: urgent, confidential, and do not use the normal process.
The supplier bank change. An email in a real thread, from a compromised or convincingly spoofed supplier address, saying the account details have changed. Often perfectly polite, often with a plausible reason, occasionally followed by a call from a familiar-sounding voice to confirm. This one is the most common and the most expensive for mid-sized firms, because it does not feel like an attack. It feels like admin.
The payroll diversion. An employee, or something that sounds like one, asks HR to update their salary account before the run. Small, routine, and it works because nobody verifies a change that small.
Notice that in all three the target is the payment instruction. The face or the voice is only the way in.
The five controls that actually work
1. Callback verification on a number you already hold
Any payment instruction that is new, changed or unusual gets verified by calling back on a number from your own records, not from the email, not from the message, and not from a number the caller gives you.
This is the control. It defeats voice cloning, because the attacker does not control the number you are dialling. It costs nothing. Write it down as a rule rather than leaving it as a habit, because habits are what pressure removes.
2. Two people on every payment above a threshold
Set a threshold you can live with and require a second authoriser above it, with the second person verifying independently rather than rubber-stamping. The value is not the second signature, it is that the attacker now has to compromise two people at once under time pressure.
3. Bank detail changes handled as their own process
Treat a change of supplier bank details as a discrete, logged process with its own verification, never as an edit to an invoice. Same for payroll destinations. Two practical additions: notify the previous contact point when details change, and impose a short mandatory delay before the first payment to new details. That delay costs you nothing legitimate and breaks the entire economics of the attack, which depends on being fast.
4. A shared phrase for urgent requests
A word or phrase agreed in advance, in person, between the people who can authorise payments. Not written in email, not stored in the shared drive. Anyone can ask for it on a call.
Low-tech, faintly ridiculous, and effective, because it verifies something the attacker cannot synthesise from public material.
5. A rule that says stopping is always acceptable
Write it down and have the owner or CEO say it out loud: no one will ever be criticised for delaying a payment to verify it, including one I appear to have asked for.
This matters more than any of the technical controls. In almost every case we have looked at, someone was uneasy and proceeded anyway, because the request came from a senior person and the perceived cost of being wrong about them was higher than the perceived cost of being wrong about the payment.
The control that does not work
Trying to detect the fake. Training staff to spot unnatural blinking, audio artefacts or lip-sync errors was reasonable advice a few years ago and is now actively harmful, because it teaches people that a call which passes inspection is genuine. Detection tools have the same problem at the institutional level: they are behind the generators, and a negative result creates confidence you have not earned.
Defend the payment. The payment is the thing you control.
Which controls stop which attack
| Control | Cloned voice or video | Compromised supplier email | Payroll diversion | Cost |
|---|---|---|---|---|
| Callback on a held number | Yes | Yes | Yes | None |
| Two authorisers above a threshold | Yes | Yes | Partially | Low |
| Bank changes as a logged process with a delay | Partially | Yes | Yes | Low |
| Agreed verification phrase | Yes | No | No | None |
| Permission to pause | Yes | Yes | Yes | None |
| Trying to spot the fake | No | No | No | Misleading |
What to do this week
- Write the payment authorisation rule. One page: thresholds, who authorises, callback requirement, and the bank-change process. If your SOPs are thin generally, the first ten SOPs every growing business needs is where to start.
- Tell the finance team about the pause rule, from the most senior person available, in a meeting rather than an email.
- Agree the verification phrase among the people who can authorise payments.
- Check your held contact numbers are current, because a callback rule with stale numbers fails quietly.
- Run one exercise. Have someone send a realistic urgent request and see what happens. It is the only way to know whether the process exists outside the document.
For the wider security baseline that sits underneath this, see cybersecurity for growing businesses, and for how senior people's devices and numbers get targeted specifically, the executive phone stack.
Frequently asked questions
Is this only a large-company problem?
The opposite. Large companies have segregated duties and payment controls. A small firm where one person can initiate and approve a transfer, and where the owner's voice is on a podcast, is a much easier target and has less capacity to absorb the loss.
What if a payment has already gone?
Contact your bank immediately and ask them to attempt a recall, then report it. Speed is the only variable that matters, and the first hours are decisive. In the US, report to the FBI's Internet Crime Complaint Center; elsewhere, to your national cybercrime authority and your bank's fraud team. Do not wait until you have worked out how it happened.
Should we buy deepfake detection software?
Not as a primary control. If you buy it, treat a negative result as meaningless and keep the callback rule regardless. The money is better spent on process and on making sure the process is followed.
Does insurance cover this?
Sometimes, and often with conditions requiring documented verification controls. Read your policy before you need it, because a claim is a bad time to discover that the callback procedure you did not have was a condition of cover. This belongs in the same review as your cash flow forecast, since a diverted payment is a cash event before it is anything else.
Where to go next
If you want the payment controls, the authorisation matrix and the supplier verification process designed and actually adopted rather than filed, that is standard business operations consulting work for us. It usually takes a week. Talk to us if you would like it looked at.