The Old Warning Signs Are Disappearing
AI-generated messages are polished and personalized enough to pass as genuine, and voice or video is no longer proof that the person on the other end is who they claim to be.
Small and midsize businesses aren't safer because they're smaller targets — they're often more attractive targets, precisely because approvals tend to be informal. A 40-person company where the CFO can greenlight a wire transfer with one phone call is an easier target than an enterprise with three layers of sign-off, not a harder one.
The New AI-Enabled Threats
The threat category has expanded well beyond the classic phishing email:
- Voice-cloned executives requesting urgent action.
- Fake vendor-payment requests that mimic a real supplier's invoicing pattern down to the formatting.
- Deepfake video meetings — not a hypothetical anymore, as the case below shows.
- Synthetic customer-support requests designed to extract account access or reset credentials.
- Fake ads and social profiles impersonating your brand to run scams under your name.
- AI-generated reviews and testimonials — both fake positive ones inflating a competitor and fake negative ones aimed at you.
How an Executive-Impersonation Attack Works
The clearest illustration of where this technology already stands happened at Arup, the global engineering firm, in January 2024. A finance employee at the company's Hong Kong office joined what appeared to be a routine video call with the CFO and several colleagues. Every person on that call except the employee was a deepfake — synthesized from publicly available video and audio of real executives.
The fake executives referenced internal information and processes to establish credibility, created social pressure through apparent consensus among multiple "colleagues," and instructed the employee to process wire transfers under artificial urgency and confidentiality. The employee complied. Over the course of that day, 15 fraudulent transfers went out totaling $25.6 million. The fraud was only discovered when the employee later followed up with actual headquarters — and learned the meeting had never happened. As of early 2025, no funds have been recovered and no perpetrators identified.
That's the pattern behind nearly every AI-impersonation attack: gather public information and media on real executives, deliver an urgent request through a channel that feels legitimate, bypass normal procedure by leaning on authority and time pressure, and get payment, credentials, or data moving before anyone stops to verify.
Why Technology Alone Cannot Stop It
This is the part that surprises people: the Arup employee wasn't careless. They were following a request that looked and sounded exactly like their real leadership, in a scenario technology alone can't reliably flag. A legitimate, well-trained employee can be the one who authorizes the transfer — because the fraud isn't exploiting a software vulnerability, it's exploiting urgency, authority, and trust.
Deepfake-detection software helps, but it's not sufficient as the only control. Detection tools have to win every single time; an attacker only needs to win once. Microsoft's own VALL-E research demonstrated that a voice can be cloned with remarkable accuracy from just three seconds of audio — a clip easily pulled from an earnings call, a conference talk, or a video posted to your own website. The bar for creating a convincing fake has dropped faster than most companies have updated their approval processes.
Controls Every Business Should Implement
None of these require new technology. They require a process that doesn't bend under urgency:
- Out-of-band verification — confirm any unusual request through a different channel than the one it arrived on.
- Dual approval for payment changes — no single person, regardless of seniority, can redirect funds alone.
- Known-number callbacks — call the person back at a number you already had on file, never one provided in the request itself.
- Vendor-change procedures — any change to banking or payment details for an existing vendor triggers manual verification, no exceptions.
- Transaction thresholds — dollar amounts above a set level automatically require a second, independent sign-off.
- Verification phrases — a pre-agreed code word for high-stakes requests that a deepfake, however convincing, won't know.
- Clear escalation rules — every employee knows exactly who to contact when something feels off, without fear of slowing down a "legitimate" request.
The FBI's Internet Crime Complaint Center recorded 24,768 business email compromise complaints in 2025, totaling just over $3.05 billion in reported losses — a 16% jump in complaints and a 10% jump in losses over 2024. Its Financial Fraud Kill Chain recovered 58% of funds flagged quickly enough in 2025, down from 66% the year before. The math on that is blunt: prevention is far more reliable than recovery, and the gap is widening.
Protecting the Brand
Impersonation risk doesn't stop at your finance department — it extends to anyone claiming to be your company in public. Brand-protection research from MarqVision found AI-driven brand-threat detections grew more than 16x year over year in Q1 2026 alone, with fake website detections up 47x and paid ad abuse up 3x. Companies dealing with counterfeiting are increasingly dealing with impersonation at the same time — 87% of businesses hit by one saw the other.
Practical steps that matter here:
- Monitor for lookalike domains and unauthorized social accounts using your brand name.
- Claim your profiles on major platforms before someone else does.
- Document your approved spokespeople internally, so employees and customers know who's authorized to speak for the company.
- Monitor for fake ads and suspicious reviews running under your name.
- Establish a takedown process and a customer-notification plan before you need one, not after.
What Employees Need to Know
The strongest control in this entire list is a well-briefed employee who trusts a process over a familiar voice. Make sure your team understands:
- Urgency is a warning sign, not a reason to skip verification — real emergencies can wait five minutes for a callback.
- A familiar voice or face on a call is no longer proof of identity.
- Never use the contact details provided within a suspicious request — look them up independently.
- Following verification procedures protects employees from blame, even when the request turns out to be legitimate. Make that explicit, or people will skip the step to avoid seeming difficult.
Create an AI-Fraud Response Plan
Prevention is the priority, but a response plan needs to exist before it's needed:
- Preserve evidence — the call recording, email headers, transaction details.
- Contact financial institutions immediately — speed determines whether funds can be frozen.
- Lock affected accounts to prevent further unauthorized access.
- Notify leadership and legal counsel without delay.
- Report through appropriate government channels — the FBI's IC3 for U.S. incidents.
- Communicate carefully with customers if their data or funds were affected, guided by counsel rather than instinct.
Replace Recognition With Verification
The uncomfortable truth is that recognizing a voice or a face used to be enough, and it isn't anymore. The businesses that hold up against this next generation of fraud aren't the ones with the best detection software — they're the ones that built a process where no single urgent request, however convincing, can move money or data without a second, independent check.
This is where our cybersecurity work extends past infrastructure and into how your business actually operates day to day — the approval chains, the vendor procedures, the employee training that technology alone can't cover. If your payment-approval process still runs on "I recognized the voice," that's the gap worth closing first.
Sources: FBI Internet Crime Complaint Center (IC3) 2025 report, Arup deepfake scam case documentation (Hong Kong, January 2024), Microsoft VALL-E research, MarqVision 2026 Brand Threat Report, Association for Financial Professionals 2026 survey.
