AEGITz · Free Resource · Print and post this

Payment Verification Protocol

Cloning a convincing voice now requires a short sample, which your executives have posted publicly in podcasts, conference talks, and webinar recordings. The defense has not changed and it is not technical.

The rule

Verification happens through a phone number you already had, not one supplied in the request.

If you verify through a channel the requester provided, you have verified nothing. Everything below is implementation detail.

When verification is required

TriggerActionWho verifies
Any payment over Callback to number on file 
Any change to banking details, at any amountCallback to the previous number on file, logged 
Any first payment to a new vendorCallback plus verification of vendor identity 
Any urgent request from an executiveCallback plus code phrase 
Any request received while the approver is travelingCallback, no exceptions 

Banking detail changes are the highest-frequency version of this fraud and the amount is irrelevant. Even if the email is genuinely from your vendor's compromised mailbox, the instruction is not.

Two people, always

The person who initiates a payment is not the person who releases it. For a very small company this can be the bookkeeper and the owner. It cannot be one person holding the whole path.

Initiator:     Releaser:     Backup releaser:  

Code phrase for voice and video requests

Treat live video as weak evidence rather than proof, particularly on a short call with poor quality. The attacker has your executive's face and voice. They do not have a phrase that was never spoken online.

Current phrase held by:     Set in person on:     Rotates every:  

Verified contact register

This is the artifact the whole control depends on, and most companies do not have it. Established at onboarding, updated only in person or by callback to the previous number.

VendorAuthorized contactVerified phone numberDate verified
    
    
    

Permission to be slow

No legitimate transaction will ever be harmed by a twenty-minute verification delay, and no employee will face consequences for delaying a payment to verify it. Urgency is the attacker's only real weapon. Removing the cost of caution disarms it.

Authorized by:  

If a fraudulent payment has already gone out

Speed matters more than anything else. The window is measured in hours and days, not weeks.

  1. Call the bank immediately. Ask specifically for a recall or a hold depending on the transfer type. Bank fraud line:  
  2. File at ic3.gov. The FBI's Internet Crime Complaint Center has an established recovery process that has clawed back a meaningful share of reported funds.
  3. Call your cyber insurance carrier before you engage anyone. Many policies have notice requirements and vendor approval conditions that affect coverage. Carrier hotline:     Policy number:  
  4. Preserve the emails, headers, and payment records. Do not delete the thread.