Attackers Are Now Calling Your Employees in Your CEO's Voice. Three Seconds of Audio Is All They Need.
Voice cloning fraud surged 1,633% in a single quarter. A convincing clone of any executive's voice can now be built from three seconds of publicly available audio — an earnings call, a podcast, a conference talk, a LinkedIn video. The attacker calls your finance team in that voice, with manufactured urgency, and asks for a wire transfer. The average loss is over $500,000. Here's how the attack works and the one defense that stops it.
The Cushman & Wakefield breach in this series started with a phone call — a human attacker social-engineering an IT help desk. The technique worked because humans are wired to be helpful and to trust a voice that sounds legitimate. Now imagine that same attack, except the voice on the phone isn't a stranger doing an impression. It's a perfect clone of your CEO. Your CFO. Your IT manager. Someone the employee has spoken to a hundred times and would recognize instantly.
That's not a future threat. It's happening right now, to businesses of every size, and the technology required has collapsed to the point where it needs no specialist expertise and almost no money. A voice can be cloned from as little as three seconds of publicly available audio. Every earnings call, conference keynote, podcast appearance, and LinkedIn video your executives have ever recorded is training data sitting on the open internet, available to anyone.
surge in deepfake-enabled vishing attacks in a single quarter
Voice-cloning vishing attacks surged more than 1,600% in Q1 2025 compared to the previous quarter in the US alone. CEO deepfake fraud now targets approximately 400 companies per day. The average loss per deepfake fraud incident exceeds $500,000. This is the fastest-growing social engineering vector documented — and small businesses are increasingly the target, not the exception.
The distinction that matters for your business: traditional business email compromise relies on spoofed email domains and written text — things employees have been trained to scrutinize for a decade. Deepfake CEO fraud exploits the human tendency to trust a familiar voice, which no amount of email-phishing training addresses. An employee who spots suspicious emails flawlessly can still authorize a fraudulent wire after a phone call in a voice they recognize.
The anatomy of a deepfake vishing attack
Why small businesses are the target, not the exception
There's a comfortable assumption that deepfake fraud is a big-company problem — that attackers building voice clones are going after Fortune 500 CFOs, not the owner of a 15-person firm. The data says the opposite. Small and mid-sized businesses are increasingly the prime target, for three specific reasons.
First, SMBs rarely have the verification controls larger companies have implemented — no callback protocol, no dual-authorization requirement for wire transfers. Second, in a small business the finance function is often a single person who takes instructions directly from the owner, which means one successful call is all it takes. Third, the owner's voice is usually more accessible — a small business owner doing a local podcast, a promotional video, or a chamber of commerce talk has handed attackers everything they need.
The five defenses — and the one that actually stops it
The verification callback — the single defense that stops the attack cold
Policy · Free · EssentialThis is the one that matters most. Any request involving money movement, payment detail changes, or credential access — regardless of whose voice makes it — must be verified by calling the person back on a known, pre-established number. Not the number they're calling from. Not a number they provide during the call. The number you already have on file.
This defense works precisely because it doesn't depend on detecting the fake. It doesn't matter how perfect the voice clone is. When the employee hangs up and calls the real executive's real number, the fraud collapses — because the real executive didn't make the request.
A verbal code word for financial requests
Policy · FreeEstablish a shared code word known only to the people authorized to request and approve financial transactions. Any voice request to move money must include the code word. A cloned voice — no matter how accurate — doesn't know the code word, because it was never spoken in any public recording.
Dual authorization for money movement above a threshold
Policy · FreeNo single employee should be able to move significant funds on the strength of one instruction. Require two authorized people to approve any wire transfer above a set threshold. Even if one is deceived by a perfect voice clone, the second provides an independent check — and fooling two people simultaneously is dramatically harder.
Train the team on the threat — not to detect it, but to expect it
Training · Low costThe goal here is not teaching employees to detect fake voices — they can't reliably do that. The goal is making sure every person who touches finances knows this attack exists, knows a familiar voice is not proof of identity, and knows urgency is a manipulation tactic. An employee who expects the attack responds to the callback rule as protection, not bureaucracy.
Reduce your executives' public voice footprint where practical
Awareness · FreeThis is the least critical defense — because the callback protocol works regardless of how much public audio exists — but it's worth awareness. Every public recording of an executive's voice is potential training data. This doesn't mean executives should stop doing podcasts or talks; it means being aware that public audio is raw material for this attack.
The connection to everything else in this series
Deepfake vishing is the same attack the Cushman & Wakefield and M&S breaches used — social engineering against a human — with the human-detection defense removed. The help desk verification protocol that was the #1 control in the Five Controls post is the same callback protocol that defeats deepfake CEO fraud. The attack got more sophisticated. The defense didn't need to.
This is the recurring lesson of the entire series, made sharper by the technology: the attacks evolve constantly, but the fundamental defenses are stable, cheap, and process-based. Attackers now have perfect voice clones. Your defense is still a phone call to a known number. That asymmetry — sophisticated attack, simple defense — is the most hopeful fact in small business security.
📚 Credential Security Series — Read the full series
Make sure the verification controls exist before the call comes. Veriti Spottr's beta is free.
Get your CyberScore →
Comments
Post a Comment