Attackers Are Now Calling Your Employees in Your CEO's Voice. Three Seconds of Audio Is All They Need.

Emerging Threat AI Fraud
July 2026  ·  7 min read

Voice cloning fraud surged 1,633% in a single quarter. A convincing clone of any executive's voice can now be built from three seconds of publicly available audio — an earnings call, a podcast, a conference talk, a LinkedIn video. The attacker calls your finance team in that voice, with manufactured urgency, and asks for a wire transfer. The average loss is over $500,000. Here's how the attack works and the one defense that stops it.


The Cushman & Wakefield breach in this series started with a phone call — a human attacker social-engineering an IT help desk. The technique worked because humans are wired to be helpful and to trust a voice that sounds legitimate. Now imagine that same attack, except the voice on the phone isn't a stranger doing an impression. It's a perfect clone of your CEO. Your CFO. Your IT manager. Someone the employee has spoken to a hundred times and would recognize instantly.

That's not a future threat. It's happening right now, to businesses of every size, and the technology required has collapsed to the point where it needs no specialist expertise and almost no money. A voice can be cloned from as little as three seconds of publicly available audio. Every earnings call, conference keynote, podcast appearance, and LinkedIn video your executives have ever recorded is training data sitting on the open internet, available to anyone.

1,633%

surge in deepfake-enabled vishing attacks in a single quarter

Voice-cloning vishing attacks surged more than 1,600% in Q1 2025 compared to the previous quarter in the US alone. CEO deepfake fraud now targets approximately 400 companies per day. The average loss per deepfake fraud incident exceeds $500,000. This is the fastest-growing social engineering vector documented — and small businesses are increasingly the target, not the exception.

The distinction that matters for your business: traditional business email compromise relies on spoofed email domains and written text — things employees have been trained to scrutinize for a decade. Deepfake CEO fraud exploits the human tendency to trust a familiar voice, which no amount of email-phishing training addresses. An employee who spots suspicious emails flawlessly can still authorize a fraudulent wire after a phone call in a voice they recognize.

3 sec of audio needed to create a voice clone with 85% accuracy — from any public recording of the target McAfee / StationX 2026
$500K+ average loss per deepfake fraud incident — with large-enterprise attacks averaging $680,000 each StationX / Brightside AI 2026
60% the rate at which people correctly detect AI-generated voices — barely better than a coin flip ZeroThreat / deepfake research 2026
Humans correctly identify a cloned voice roughly 60% of the time — barely better than chance. This is the core of why the attack works and why awareness training alone can't stop it. You cannot train an employee to reliably hear the difference between your real CEO and a clone, because the difference is often inaudible. The defense cannot be "learn to recognize fake voices." The defense has to be a process that doesn't depend on the voice being real.

The anatomy of a deepfake vishing attack

How a deepfake CEO fraud attack actually works
Step 1 Harvest the voice. The attacker collects public audio of a target executive — an earnings call, a conference talk, a podcast, a webinar, a LinkedIn video, even a voicemail greeting. Three seconds is enough. For an SMB owner, a single promotional video or podcast appearance provides more than enough training data. No contact with the target required.
Step 2 Map the org chart. The attacker researches who controls the finances and who would plausibly receive a request from the executive. LinkedIn, the company website, and press releases provide this. They identify the finance manager, bookkeeper, or assistant most likely to act on an urgent instruction. Public information, freely available.
Step 3 Manufacture urgency. The attack is timed for maximum pressure — end of quarter, the executive "traveling" and unreachable by other means, a deal that will "fall through" without immediate action. Urgency is the weapon that suppresses the instinct to verify. The clock is the real attacker.
Step 4 Place the call. The cloned voice calls or leaves a voicemail — sometimes live, sometimes pre-recorded. The voice is unmistakably the executive's. The request: authorize a wire transfer, change payment details for a vendor, or provide credentials for "urgent" system access. The employee hears their boss. They comply.
Step 5 Move the money. Once the transfer is authorized, the funds move through a chain of accounts and are frequently unrecoverable within hours. By the time the real executive is reached and the fraud is discovered, the money is gone. Average loss: over $500,000.
The most sophisticated documented version of this attack went beyond a phone call. In one widely reported case, a finance employee joined a video conference with what appeared to be the CFO and several colleagues — every face and voice on the call was an AI-generated deepfake. The employee, convinced by a room full of familiar faces, authorized a multi-million-dollar transfer. Voice cloning is the entry-level version of this threat. The technology is only moving in one direction.

Why small businesses are the target, not the exception

There's a comfortable assumption that deepfake fraud is a big-company problem — that attackers building voice clones are going after Fortune 500 CFOs, not the owner of a 15-person firm. The data says the opposite. Small and mid-sized businesses are increasingly the prime target, for three specific reasons.

First, SMBs rarely have the verification controls larger companies have implemented — no callback protocol, no dual-authorization requirement for wire transfers. Second, in a small business the finance function is often a single person who takes instructions directly from the owner, which means one successful call is all it takes. Third, the owner's voice is usually more accessible — a small business owner doing a local podcast, a promotional video, or a chamber of commerce talk has handed attackers everything they need.

The three-second requirement is what makes this an SMB threat, not just an enterprise one. A Fortune 500 CEO and a 20-person company owner are equally cloneable from a single public recording. The difference is that the enterprise has likely implemented callback verification and dual-authorization controls, and the small business often hasn't. The attack is the same. The defense gap is wider for the small business.

The five defenses — and the one that actually stops it

1

The verification callback — the single defense that stops the attack cold

Policy · Free · Essential

This is the one that matters most. Any request involving money movement, payment detail changes, or credential access — regardless of whose voice makes it — must be verified by calling the person back on a known, pre-established number. Not the number they're calling from. Not a number they provide during the call. The number you already have on file.

This defense works precisely because it doesn't depend on detecting the fake. It doesn't matter how perfect the voice clone is. When the employee hangs up and calls the real executive's real number, the fraud collapses — because the real executive didn't make the request.

Implement todayWrite one rule: "Any request to move money, change payment details, or share credentials must be verified by calling the requester back on their known number before any action — no exceptions, regardless of urgency." Send it to everyone who touches finances. This single policy defeats the entire attack class.
2

A verbal code word for financial requests

Policy · Free

Establish a shared code word known only to the people authorized to request and approve financial transactions. Any voice request to move money must include the code word. A cloned voice — no matter how accurate — doesn't know the code word, because it was never spoken in any public recording.

Implement this weekAgree on a code word with your finance team and anyone authorized to approve transfers. Change it periodically. Never send it in writing over email or text — establish it in person or over a verified channel. If a "CEO" calls asking for a transfer and can't provide the code word, the request is fraudulent.
3

Dual authorization for money movement above a threshold

Policy · Free

No single employee should be able to move significant funds on the strength of one instruction. Require two authorized people to approve any wire transfer above a set threshold. Even if one is deceived by a perfect voice clone, the second provides an independent check — and fooling two people simultaneously is dramatically harder.

Set the thresholdPick a dollar amount appropriate to your business — anything above it requires two named approvers. Document it. Communicate it to your bank if they offer dual-authorization controls on your accounts. Many business banking platforms support this natively.
4

Train the team on the threat — not to detect it, but to expect it

Training · Low cost

The goal here is not teaching employees to detect fake voices — they can't reliably do that. The goal is making sure every person who touches finances knows this attack exists, knows a familiar voice is not proof of identity, and knows urgency is a manipulation tactic. An employee who expects the attack responds to the callback rule as protection, not bureaucracy.

The core message"Live audio and video can be faked. A voice you recognize is not proof of who's calling. Urgency is part of the attack. Verification on a second trusted channel is always required — and it's never an insult to the person asking." Reinforce it quarterly.
5

Reduce your executives' public voice footprint where practical

Awareness · Free

This is the least critical defense — because the callback protocol works regardless of how much public audio exists — but it's worth awareness. Every public recording of an executive's voice is potential training data. This doesn't mean executives should stop doing podcasts or talks; it means being aware that public audio is raw material for this attack.

The realistic takeawayYou cannot eliminate your public voice footprint, and you shouldn't try to. Public visibility is valuable. Instead, assume your voice is already cloneable — because it likely is — and build the verification controls that make the clone useless. The callback protocol is the answer, not audio secrecy.
Notice the pattern across all five defenses: not one of them depends on detecting the fake voice. Every effective defense against deepfake vishing is a process that makes the authenticity of the voice irrelevant. This is the key insight. The technology to detect clones will always lag the technology to create them. The verification process — call back on a known number, use a code word, require dual authorization — works today and will keep working no matter how perfect the clones become.

The connection to everything else in this series

Deepfake vishing is the same attack the Cushman & Wakefield and M&S breaches used — social engineering against a human — with the human-detection defense removed. The help desk verification protocol that was the #1 control in the Five Controls post is the same callback protocol that defeats deepfake CEO fraud. The attack got more sophisticated. The defense didn't need to.

This is the recurring lesson of the entire series, made sharper by the technology: the attacks evolve constantly, but the fundamental defenses are stable, cheap, and process-based. Attackers now have perfect voice clones. Your defense is still a phone call to a known number. That asymmetry — sophisticated attack, simple defense — is the most hopeful fact in small business security.

The Veriti Spottr CyberScore's Security Posture survey covers the verification and authorization controls that defend against social engineering — including the callback protocols and dual-authorization practices that stop deepfake CEO fraud. The threat is evolving toward perfect voice and video clones. The defense is the same process-based verification that stops every social engineering attack in this series. Your CyberScore tells you whether that process exists in your business — before a voice you recognize asks for a transfer you can't get back.

Make sure the verification controls exist before the call comes. Veriti Spottr's beta is free.

Get your CyberScore →
VS
Veriti Spottr Team AI-powered cyber risk clarity for SMBs  ·  veritispottr.com

Comments

Popular posts from this blog

Your Password Policy Isn't Protecting You. Your Employees' Habits Are.

What Attackers Do With Your Data in the First 60 Minutes

A Major UK Retailer Had 70 Days to Stop the Attack. They Didn't Know It Was Happening.