Security

That Wasn’t Your CEO on the Phone

By August 20, 2026 No Comments
A smartphone on a desk with a sound waveform that fractures into red digital fragments, representing an AI-cloned voice on a fraudulent phone call

Your bookkeeper gets a call. It’s the owner — same voice, same speech patterns, slightly rushed. There’s a wire that has to go out before end of day, the details are in an email, and he’s about to board a flight so don’t bother calling back.

Everything about it sounds right. Because the voice is right. It was built from a thirty-second clip of him talking, pulled off the company’s own website.

This is the fraud that skips your email filters entirely. No suspicious link, no spoofed domain, nothing for your security tools to catch. Just a phone call that sounds exactly like someone your staff trusts.

This Is Already Happening at Real Companies

The most expensive confirmed case hit the engineering firm Arup in early 2024. An employee in their Hong Kong office joined a video call with what appeared to be the company’s CFO and several colleagues. Every participant except the victim was synthetic.

She made fifteen transfers totaling roughly $25 million.

Two other attempts show what stopping it looks like. Criminals impersonated WPP’s CEO using a cloned voice and a fake Teams meeting — and failed. At Ferrari, an executive on a call with a convincing fake “CEO” simply asked a question only the real one could answer. The call ended immediately.

The pattern is worth noticing: the attacks that failed were stopped by a person asking for verification, not by software.

Why This Suddenly Got Easy

Voice cloning used to require a research lab. Now it requires a credit card and a few seconds of audio.

Commercial voice cloning tools start around $6 a month. Open-source versions are free. Industry analysis from the financial sector’s own information-sharing body notes that only a few seconds of training audio are enough for a successful attack.

And here’s the uncomfortable part: your audio is already public. A podcast interview. A conference talk. A webinar recording. Your voicemail greeting. A video on your own About page. If your voice exists online, the sample is already collected.

Small businesses often assume they’re too small to target. But this attack doesn’t require researching a Fortune 500 org chart — it requires knowing who signs off on payments. That’s usually posted on your website.

The Numbers, Honestly

There’s a lot of inflated statistics circulating on this topic, so here’s what the government data actually says.

The FBI’s 2025 Internet Crime Report tracked AI-related fraud for the first time. Business email compromise cases with a documented AI element accounted for just over $30 million in reported losses across 135 complaints. Business email compromise overall — AI or not — ran to more than $3 billion.

So no, AI voice fraud is not yet the biggest category of business fraud. But the FBI notes those AI figures are a floor, because reporting is voluntary and most victims never know whether AI was involved. A cloned voice on a phone call leaves no evidence behind.

The mechanism that matters hasn’t changed: money leaves by wire or ACH, and roughly 86% of business email compromise losses move that way. AI didn’t invent this fraud. It made the convincing part cheap.

The One Control That Beats All of It

Here’s the good news, and it’s genuinely good: you cannot detect a modern voice clone by ear, but you don’t have to.

The defense is procedural, not technical. Any request to move money or change payment details gets verified through a different channel than the one it arrived on. Every time, no exceptions, regardless of who appears to be asking.

The FBI’s guidance is direct about this — hang up, independently look up the number for that person, and call them back. Don’t use a number provided in the request. Don’t reply to the email thread. Don’t call back the number that just called you.

This works because it doesn’t rely on detecting the fake. It doesn’t matter how perfect the voice is if the confirmation happens somewhere the attacker doesn’t control. As one financial-sector guidance document puts it, insist on calling back on a known good number and fraudsters will likely just end the interaction.

That’s exactly what happened at Ferrari.

Write the Policy This Week

This is a one-page document and an afternoon of conversation. It does not require new software.

Define what triggers verification. Any new payee. Any change to existing banking details. Any wire above a dollar amount you set. Any payment request marked urgent.

Specify the callback method. A phone number from your own records — your accounting system or vendor file, not the request. Write down where that number comes from.

Require two people for changes to banking details. One person verifies, a second approves. This single step blocks most versions of this fraud.

Consider a verbal code phrase for executives authorizing unusual payments. The FBI specifically recommends this. It’s low-tech and a voice clone can’t guess it.

Tell your team that urgency is the red flag. Not a bad accent, not a weird email address — urgency combined with secrecy. Real executives do not punish people for verifying. Make that explicit, because the whole attack runs on an employee’s fear of annoying the boss.

The Part Most Policies Miss

Your staff must have explicit permission to slow down a request from the owner.

Every one of these frauds depends on someone deciding it would be awkward to double-check. If your bookkeeper believes calling you back to confirm a wire is going to irritate you, no written policy will save you.

Say it out loud in a staff meeting: if I ever call asking you to move money urgently, hang up and call me back. I will never be annoyed. Then thank the person who actually does it.

If It Already Happened, Move Fast

Time matters enormously with wire fraud. Call your bank immediately and ask about a wire recall, then file with the FBI at ic3.gov. Federal guidance notes recovery odds are dramatically better inside the first 24 hours.

Don’t spend the morning investigating internally first. Call the bank, then investigate.

A Half-Hour Conversation

Most businesses we work with around Castle Rock and the Denver metro have no written verification procedure at all — not because they don’t care, but because nobody ever told them this was the gap. Payment approval lives in habit and trust rather than in a process.

Habit and trust used to be enough. A $6 voice clone changed that math.

If you’d like help writing a verification policy that fits how your business actually operates — and training your team on it — reach out to Castle Rock Sky. It’s a short conversation that costs you almost nothing, and it’s considerably cheaper than the alternative.