The Voice on the Phone Is Not Your CFO
Voice cloning and deepfake video have made verbal authorization worthless. The callback rule that stops wire fraud, written so your bookkeeper can follow it.
The short answer
The control that stops deepfake and wire fraud is one sentence: verification happens through a phone number you already had, not one supplied in the request. Every banking detail change gets a callback regardless of amount, payments above a set threshold require two people, and no employee faces consequences for delaying a payment to verify it.
The controls most small businesses use to authorize a payment were designed for a world where impersonating a specific person's voice was hard. That world is over. Cloning a convincing voice now requires a short sample, which your executives have posted publicly in podcasts, conference talks, and webinar recordings.
The good news is that the defense has not changed and it is not technical. It is a procedure, and it works as well against a cloned voice as it did against a forged fax.
What the current version of this fraud looks like
The pattern has three stages.
First, reconnaissance. The attacker learns your org chart from LinkedIn, your vendor relationships from press releases and job postings, and your executive voices from any public recording. If they have compromised a mailbox anywhere in your supply chain, they also have your invoice formats and your payment history.
Second, pretext. A message arrives that is contextually correct. It references a real project, a real vendor, and a plausible amount. Timing is chosen deliberately: Friday afternoon, the day before a holiday, while the executive is traveling and hard to reach.
Third, pressure with a verification path the attacker controls. This is the critical move. The request will include a phone number to call, a new contact to confirm with, or a video call that is very short and slightly glitchy. If you verify through a channel the attacker supplied, you have verified nothing.
The callback rule
One sentence, and it is the entire control.
Verification happens through a phone number you already had, not one supplied in the request.
Everything else is implementation detail. Write it into your payment procedure, train on it, and enforce it without exception, including for the CEO. Especially for the CEO, since executive exception is the specific hole these attacks are built to exploit.
The procedure that goes with it
Set a threshold. Any payment over an amount you choose, plus any change to banking details at any amount, requires verification.
Banking detail changes deserve special mention because they are the highest-frequency version of this fraud and the amount is irrelevant. A vendor emails to say their bank has changed. Even if the email is genuinely from their compromised mailbox, the instruction is not. Every banking change gets a callback to your existing number for that vendor, no exceptions, and the confirmation gets logged.
Maintain a verified contact list. A short document with each vendor's authorized contact and phone number, established at onboarding and updated only in person or by callback to the previous number. This is the artifact the whole control depends on and most companies do not have it.
Require two people. The person who initiates a payment is not the person who releases it. For a very small company this can be the bookkeeper and the owner. It just cannot be one person with the whole path.
Give people permission to be slow. State plainly and in writing that no legitimate transaction will ever be harmed by a twenty-minute verification delay, and that no employee will face consequences for delaying a payment to verify it. Urgency is the attacker's only real weapon. Removing the cost of caution disarms it.
What to do about video
Live video used to be reasonable verification. Treat it now as weak evidence rather than proof, particularly on a short call with poor quality.
If you want a verification method that works over video, use a shared secret established out of band. A code phrase set in person, rotated periodically, known to the small group authorized to approve payments. It is low technology and it works, because the attacker has your executive's face and voice but not a phrase that was never spoken online.
If it already happened
Speed matters more than anything else. Call your bank immediately and ask specifically for a SWIFT recall or a hold, depending on the transfer type. Then file with the FBI's Internet Crime Complaint Center at ic3.gov. Their recovery asset team has an established process and it has clawed back a meaningful share of reported funds, but the window is short and measured in hours and days, not weeks.
Then call your cyber insurance carrier before you begin remediation, because many policies have notice requirements and vendor approval conditions that can affect coverage.
Get the protocol
The Payment Verification Protocol is a one-page document you can post next to the desk of whoever cuts checks. It has the threshold table, the callback script, the banking change procedure, the verified contact register, and the incident steps with the phone numbers already filled in.
Print it. It works better on the wall than in a folder.
Frequently asked questions
How do you prevent deepfake wire fraud?
Verify through a phone number you already had on file, never one provided in the request itself. Cloning a voice now requires only a short public sample, so verbal authorization is no longer proof of identity. The defense is procedural rather than technical and works as well against a cloned voice as it did against a forged fax.
Is video call verification still safe?
Treat live video as weak evidence rather than proof, particularly on a short call with poor quality. If you want verification that works over video, use a shared code phrase established in person and rotated periodically. The attacker has your executive's face and voice but not a phrase that was never spoken online.
What should I do immediately after a fraudulent wire transfer?
Call your bank immediately and ask specifically for a recall or hold depending on the transfer type, then file with the FBI Internet Crime Complaint Center at ic3.gov, then notify your cyber insurance carrier before beginning remediation. The recovery window is measured in hours and days rather than weeks.
Why do banking detail change requests deserve special handling?
They are the highest-frequency version of this fraud and the amount is irrelevant. Even when the email genuinely comes from your vendor's compromised mailbox, the instruction is not theirs. Every banking change gets a callback to your existing number for that vendor, with the confirmation logged.
Related reading
- Your AI Tools Have Logins Now, and Nobody Is Managing Them
- MFA Stopped Being Enough About Two Years Ago
- The Microsoft 365 Settings Most Phoenix Businesses Never Turned On
- Anyone Can Send Email as Your Company Until You Fix This
- Your Weakest Security Control Belongs to Somebody Else
- Offboarding an Employee in 60 Minutes
