Deepfake and Voice Cloning Fraud: What Businesses Should Do
A familiar voice on the phone and a face on a video call are no longer proof of anything. The defences that still work are process, not technology.
“If an email looks odd, pick up the phone and check.” That was the standard advice on payment fraud, it was good advice, and it is now incomplete. Occasionally it is the trap itself.
Fraud has moved. The email that once carried a slightly wrong domain name and a stiff turn of phrase has been joined by a voice on the telephone that sounds exactly like your managing director, and a face on a video call that looks exactly like your finance lead. Both can now be manufactured cheaply, from material that is already public.
What has actually changed
Voice cloning needs very little to work with. A short sample is enough — a voicemail greeting, a few seconds of a conference recording, a clip from a company video, a podcast interview. Anyone who has ever spoken publicly, and most business owners have, is already sampled. There is no way to take that back.
The classic setup follows a familiar shape. A message arrives on WhatsApp or a text, apparently from a director, apologising for the odd number and explaining they are travelling. It asks for a quick, urgent favour, usually a payment that must go today, usually with a plausible reason for the secrecy: a deal in progress, an acquisition, a supplier threatening to withhold. If the member of staff hesitates, a call follows. The voice is right. The manner is right. The pressure is gentle and personal rather than aggressive.
Video calls have followed. There have been widely reported cases in which staff joined a meeting with what appeared to be senior colleagues and authorised transfers on the strength of it, only for the whole call to turn out to be fabricated. Whatever the details, the lesson holds: seeing a familiar face on a screen is no longer evidence that the person is in the room.
The uncomfortable consequence is that identity can no longer be verified through the channel where the request arrives. It has to be verified out of band, on a route the fraudster does not control.
Why technology is not the answer here
It is tempting to look for a filter, and there are products that claim to spot synthetic audio and video. Treat them as a marginal help rather than a control. Real-time detection has to work with compressed, degraded audio on a phone line or a patchy video feed — precisely the conditions in which the tell-tale artefacts disappear. And every improvement in detection is met by an improvement in generation.
So build the defence where the money moves, not where the fake arrives. The controls below work regardless of how convincing the impersonation is, which is the property you want.
The process controls that hold
A fixed callback rule. Any request to move money, or to change where money goes, is verified by calling the person back on a number from your own records. Not the number in the message. Not a number offered during the call. Your records — the HR file, the signed supplier form, the contact list you maintain. Write this down as a rule so nobody has to invent it under pressure.
Dual authorisation over a threshold. Set an amount above which two named people must approve a payment, and apply the same requirement to every change of bank details regardless of value. Two people is not twice the security; against a scam that depends on isolating one person, it is a categorically different obstacle.
Bank-detail changes never actioned on an email or a call alone. This is the single highest-value rule in the list. Treat any change of account number as suspicious by default. Verify it by callback to a known number, have a second person confirm, and record who did both. The same applies to a supplier’s “new” details, a landlord’s, and a member of staff’s payroll account.
An agreed challenge question or safe word for finance staff. A detail no attacker can research — not a birthday, not a school, but something from a shared, unrecorded moment. If a caller claiming to be a director cannot produce it, the conversation ends and the callback rule takes over.
Permission to slow things down. This one is cultural, and it is the one that fails most often. Every scam of this type relies on a junior person feeling unable to question a senior one. If your finance assistant believes that pausing a payment from the boss will get them a telling-off, your other controls do not matter. Say out loud, in a meeting, that nobody will ever be criticised for delaying a payment to check it. Then mean it the first time someone does.
Rehearse these the way you would a fire drill. Regular security awareness training that includes a realistic urgent-request scenario is worth more than a policy document nobody has opened, because it converts a rule into a reflex.
Where this fits with the fraud you already know about
Impersonation of this kind usually rides on the same rails as older business email compromise: a compromised or spoofed mailbox, a redirected invoice, a supplier’s account details quietly changed. If you have not already worked through the fundamentals there, start with our guide to invoice fraud and BEC — the mailbox hygiene, the forwarding-rule checks and the supplier verification steps in it are the foundation this sits on.
Deepfakes do not replace that playbook. They remove one of the checks people relied on inside it, which means the remaining checks have to be firmer and genuinely followed.
Do this month
Write the callback rule and the dual-authorisation threshold on one page. Agree the safe word with whoever handles payments. Tell the whole team, plainly, that verifying a request from a director is expected behaviour rather than an insult. None of it costs anything, and all of it works against a fake you cannot detect.
If you would like a second opinion on where your payment process could be pushed, our cyber security reviews look at exactly these habits alongside the technical controls — and we will tell you honestly which of the two you should fix first.
Frequently asked questions
Can software detect a deepfake voice or video call?
Not reliably, and we would not build a defence on it. Detection tools exist, they improve, and the fakes improve alongside them. Anything running in real time on a phone call or a video meeting is working with compressed, low-quality audio and video, which is exactly the condition that hides artefacts. Assume a good fake will pass, and put the control in the process instead.
How much of someone's voice does a cloner need?
Far less than people expect. Current tools work from a short sample — the length of a voicemail greeting, a conference talk, a podcast appearance or a clip from social media. For anyone whose voice is published anywhere, and that includes most directors, the raw material is already public. There is no realistic way to withdraw it.
What should staff do if a call feels wrong but they can't say why?
Hang up and call back on a number from your own records. That is the whole answer, and it needs to be socially acceptable in your business. Frame it as following the process rather than accusing anyone — "I'll ring you back on the office number, it's just what we do now" is a complete and polite response that costs nothing if the call was genuine.
Related services
Want a hand with any of this?
Tell us what you're trying to sort out and we'll come back with a clear, no-obligation plan and price.
