Blog · Fraud Prevention · July 12, 2026 · By Mike Parker

Deepfake Voices, Real Wire Transfers

Business email compromise grew up. It calls now — in your CEO's actual voice. Here's how AI changed the oldest con in business, and the verification protocols that still beat it.

It's 4:47 on a Friday afternoon when the controller's phone rings. It's the CEO — the voice, the cadence, the trademark impatience. "I'm about to board a flight. The acquisition deposit has to go out before the bank's cutoff. Legal will send the details. Keep it between us until Monday — and don't call back, I'll be in the air." The wire goes out at 5:04. The CEO lands two hours later and has no idea what anyone is talking about.

Nothing in that story required a hacker. It required about thirty seconds of the CEO's voice — harvested from a podcast, an earnings call, a conference panel — and software anyone can rent.

BEC was already the expensive one

Business email compromise has quietly out-earned flashier crimes for years. The playbook is simple: impersonate someone the victim trusts — an executive, a vendor, an escrow officer — and redirect a payment that was going to happen anyway. No malware, no ransom note, just persuasion aimed at the person who moves money. Per the FBI's IC3 2025 report, U.S. businesses reported $3.05 billion in BEC losses in a single year — and that's only what got reported.

Email defenses got better, and employees learned to squint at odd grammar and lookalike domains. So the con evolved.

What AI changed

  • Voice cloning got cheap. A short sample of someone speaking — and executives are the most-recorded people in any company — is enough for a convincing clone. The "urgent call from the boss" now survives the victim actually knowing the boss.
  • Video joined the game. In one widely reported 2024 case, a finance employee in Hong Kong joined a video call where every other participant — including the chief financial officer — was a deepfake, and approved transfers worth more than $25 million. Seeing is no longer believing.
  • The tells are gone. Broken English and clumsy formatting used to do half of your security training's job. AI writes flawless, in-voice email — and it can write a hundred variants, personalized from scraped social profiles, in the time it used to take to write one.
  • The target list got longer. When each attempt costs pennies, criminals don't need whales. A 20-person escrow office is worth the effort now.

What didn't change: the psychology. Every one of these frauds still runs on the same three levers — urgency (before the cutoff), authority (the boss said so), and secrecy (keep it quiet). AI just made the authority lever nearly perfect. Your defense, therefore, can't live in anyone's ears or eyes. It has to live in process.

The scoreboard

The con that out-earns the hackers

The FBI's Internet Crime Complaint Center tallies what victims report. The real numbers are higher — embarrassment keeps plenty of wires out of the statistics.

$3.05B

in reported U.S. BEC losses in one year — no malware required

FBI IC3 2025

$20.9B

in total reported U.S. cybercrime losses in 2025

FBI IC3 2025

26%

jump in reported losses in a single year — the curve is bending the wrong way

FBI IC3 2025

Verification protocols that survive a perfect voice

The good news: the countermeasures are procedural, cheap, and boring. They work precisely because they don't depend on anyone detecting a fake.

  1. The callback rule. Any payment instruction or banking-detail change that arrives by email, text, or phone gets verified by calling the requester at a number already on file — never a number provided in the request. No exceptions for urgency. Urgency is the tell.
  2. Dual approval on money movement. Two named humans must approve any wire above a threshold you set — and every change to vendor banking details, regardless of amount. No single person in the company, including the owner, can move money alone. That single sentence, enforced, defeats most of this crime category.
  3. Out-of-band confirmation. The confirmation must travel on a different channel than the request. Email request? Verify by phone. Phone request? Verify in your accounting system's vendor record or face to face. Same channel = same attacker.
  4. A verification phrase for executives. A shared code word for genuinely urgent requests costs nothing and instantly defeats a cloned voice that doesn't know it.
  5. A culture where the boss loves being verified. This is the one that fails in real life. If the CEO gets snippy about callbacks, the protocol is dead. Put it in writing: "Verification applies to everyone, especially me." Then praise the employee who verifies — publicly.

Train the people who touch money — AP, finance, escrow officers, anyone with wire authority — on these specifically. It's a different curriculum than "don't click links."

The technical layer still matters

Process is the last line; technology thins the herd before it gets there. An effective security stack for BEC includes email authentication (SPF, DKIM, and DMARC at enforcement) so criminals can't send mail as your domain, an email security gateway that flags lookalike domains and external senders; and MFA on every mailbox. Add monitoring for the classic staging moves, because so many of these frauds begin with a quietly compromised inbox: new forwarding rules, impossible-travel sign-ins, thread hijacking. That last part is identity threat detection, and we wrote a plain-English guide to ITDR if you want the full picture.

If a wire already went out

Minutes matter more than anything you'll do later. Call your bank's fraud line immediately and request a recall and freeze. File at ic3.gov right away — the FBI's Recovery Asset Team exists for exactly this, and its odds improve dramatically with speed. Notify your cyber insurance carrier (social-engineering coverage usually has prompt-notice conditions), preserve every email and call record, and save the analysis for after the money is chased.

A note for the industries that live on wires: escrow and title companies, law firms, and CPA practices are this crime's favorite habitat, because large transfers to new destinations are their normal Tuesday. We work with real estate and escrow firms and accounting practices on exactly these controls.

You can no longer trust your ears. You can still trust your process — if you build one before the Friday call comes.

Quick answers

Deepfake fraud, answered plainly

What is business email compromise (BEC)?

BEC is a fraud in which a criminal impersonates someone your company trusts — an executive, a vendor, an attorney, a title officer — and talks an employee into sending money or changing payment details. There is usually no malware and no "hack" in the movie sense; the weapon is a convincing message. It is one of the most expensive cybercrimes in America: per the FBI's IC3 2025 report, U.S. businesses reported $3.05 billion in BEC losses in a single year.

Can a scammer really clone a voice from a few seconds of audio?

Yes. Commercially available AI tools can produce a convincing clone from a short sample, and executives are the easiest people in your company to sample — earnings calls, podcasts, conference panels, webinars, even a voicemail greeting. Assume any voice that exists in public recordings can be reproduced, and design your payment controls so a voice alone is never sufficient authorization.

What is a callback rule?

A standing policy that any payment instruction or banking-detail change received by email, text, or phone call must be verified by calling the requester back at a number you already have on file — never a number supplied in the request itself. The callback goes to the known number even if the original call sounded exactly right, because the whole point is that "sounded right" no longer proves anything.

Does cyber insurance cover a fraudulent wire transfer?

Sometimes, partially. Social-engineering fraud is often covered under a separate rider with a much lower sublimit than the headline policy, and carriers may condition payment on you having followed your own verification procedures. Read the sublimit, read the conditions, and treat insurance as the backstop — the verification protocol is the actual control.

What should we do in the first hour after discovering a fraudulent transfer?

Call your bank's fraud department immediately and request a recall and freeze — speed matters more than anything else. File a complaint at ic3.gov right away; the FBI's Recovery Asset Team can attempt to freeze funds when notified quickly. Notify your insurance carrier, preserve the original emails and call records, and only then start the internal post-mortem.

Would your payment process survive a perfect fake?

A free 30-minute assessment with the owner — we'll walk your wire-approval and email defenses and tell you where the gaps are. No pitch deck, no obligation.

Book a Free 30-Minute IT Assessment