Finance employee on a video call with a deepfake of the company CEO

Urgent, secret and from the boss? Verify before you pay. 📞🔒

Deepfake voice scams: protect your business from fake CEOs

In early 2024, a finance employee at the Hong Kong office of Arup, the global engineering firm, joined a video call with the company's UK-based CFO and several colleagues. Faces he knew. Voices he knew. An urgent, confidential transaction that needed to move quickly.

Over the following days he made 15 transfers totalling around HK$200 million, roughly US$25 million. Every other person on that call was a deepfake. 😶

He had actually been suspicious of the first email. The video call is what convinced him. Every business owner should think hard about that detail.

How 30 seconds of video becomes a voice clone

So how does a criminal end up sounding exactly like your CEO? Think of your voice like your handwritten signature. For centuries, a signature felt personal and hard to fake. Then photocopiers and scanners arrived.

AI voice cloning is the photocopier for voices. Modern tools need only a short, clean sample, often 30 seconds or less, to reproduce someone's tone, accent and rhythm of speech.

And attackers usually find that sample in public:

  • 🎤 Conference talks and webinar recordings
  • 📱 LinkedIn and social media videos
  • 🎙️ Podcast interviews and investor calls
  • 📞 Voicemail greetings

Add an org chart pieced together from LinkedIn and an email from a lookalike domain, and the attacker has everything needed to "be" your CEO for five minutes. Video deepfakes take more effort, but as Arup showed, they are already good enough.

The three moments attackers strike

Timing matters just as much as the fake itself. Deepfake fraud isn't random. Attackers pick moments when pressure is high and checking is inconvenient:

  • Month-end and quarter-end: finance is busy, payments are flowing, and one more urgent transfer doesn't stand out.
  • Travel days: "I'm about to board, I can't talk long" explains a poor line, odd timing, and why the boss can't be reached any other way.
  • "Confidential deals": an acquisition or legal settlement nobody else may know about, which conveniently stops the employee from asking a colleague.

Notice the pattern: each scenario is designed to isolate one person and take away their time to think.

Why "I recognised his voice" is no longer proof

Which brings us back to the signature. Banks stopped trusting a signature on its own long ago; they check it against something else. Voices and faces now need exactly the same treatment.

Our brains are wired to trust familiar voices. That instinct served us well for thousands of years. Now it works against us, because recognition only tells you what someone sounds like, not who is actually on the line.

Caller ID, Teams display names and WhatsApp profile photos can all be faked too. So the lesson isn't "be more suspicious" (vigilance fades by Friday afternoon). It's to stop treating a voice or video call as approval at all.

The callback rule, safe words and dual approval

The good news: the controls that would have stopped a US$25 million deepfake cost almost nothing.

The callback rule

Any request to move money or change bank details is verified by calling the person back on a number already stored in your company directory. Never use the number in the email, message or incoming call. Hang up, then dial out.

Safe words

Agree a verbal passphrase between executives and finance staff, shared in person and never written in email or chat. An AI clone can copy a voice, but it can't guess a word it has never heard.

Dual approval

Payments above a set threshold need two people to approve them inside your banking platform or finance system, not over a call. One person can be fooled. Two people following a documented process are far harder to fool.

Put these rules in writing, and make it clear that the CEO will never be offended by a callback. That permission matters as much as the policy itself.

A 5-minute drill to run with your finance team

Want to test whether your team is ready? You don't need a workshop. Take the first five minutes of your next finance meeting and run this drill:

  1. Read the scenario (1 min): "The CEO calls from an airport. A confidential acquisition closes today. Wire €48,000 to this new supplier account and don't mention it to anyone."
  2. Ask for the first move (1 min): each person says what they would do. The right answer: end the call and call back on the known number.
  3. Check the directory (1 min): confirm everyone knows where verified numbers are kept and that they are up to date.
  4. Confirm the approval path (1 min): who is the second approver, and what is the threshold?
  5. Agree the escalation (1 min): who do they tell when something feels off? Confirm that nobody gets blamed for a false alarm. ✅

Repeat the drill every quarter with a new scenario. Rehearsal is what turns a written policy into a reflex.

Deepfakes will keep improving, so your defence can't depend on spotting them. It has to rely on a process that holds even when the fake is perfect, built on staff awareness training and hardened payment approval workflows. Explore our cybersecurity solutions to see how Andi-Tech can help you put that process in place.

🛡️ Make sure your next "urgent CEO call" can't cost you a cent
Andi-Tech runs deepfake and social engineering awareness training for finance teams and hardens your payment process with callback rules, dual approval and verified contact directories, so your team relies on a process instead of instinct.

Contact us at info@andi-tech.com — let's get your finance team drilled and ready before the attackers call.