Deepfake fraud has moved from novelty to working business attack, and the defense is not the one most people reach for.
Your controller’s phone rings at 4:40 on a Friday. The caller ID shows your mobile number. The voice is yours, including the habit you have of starting a sentence, stopping, and restarting it. You tell her the acquisition you have been quietly working on is closing early, the attorney needs a deposit wired before the bank cuts off at five, you are about to board a plane, and nobody in the office can know yet because the seller has not told his own staff.
Nothing in that call misrepresents how the technology works. The caller ID genuinely shows your number, because caller ID was never an authentication system. The voice genuinely is yours, in the sense that it was built from recordings of you. Some current voice models need only a few seconds of clean audio, and you have given the internet far more than that: a webinar, a chamber of commerce video, a podcast appearance, the outgoing greeting on your own phone system.
The only false thing in that call is the identity of the person on the other end, and that is exactly the one thing your controller cannot verify by listening harder. So this post argues something that cuts against most advice on the topic: detection is a dead end for a small business. The answer is a payment process that does not care whether the voice is real.
What happened at Arup, and why the standard advice failed
In January 2024, a finance employee at the Hong Kong office of Arup, the British engineering firm behind the Sydney Opera House, received an email that appeared to come from the company’s UK based chief financial officer. It described a confidential transaction. The employee was suspicious, and he was right to be. That is what awareness training is supposed to produce.
So he did the responsible thing. He asked for a video call to confirm.
On the call was the CFO. Also on the call were several colleagues he recognized. They looked right. They sounded right. They confirmed the request in real time. His suspicion collapsed under the weight of what appeared to be corroboration from multiple familiar people, and he executed 15 transfers across five Hong Kong bank accounts totaling roughly 200 million Hong Kong dollars, about 25.6 million US dollars. Every single participant on that call except him was synthetic. The fraud surfaced only when he followed up with head office directly. Arup confirmed the incident publicly in May 2024, stating that fake voices and images had been used and that none of its internal systems were compromised. The company’s chief information officer described it as technology enhanced social engineering.
Sit with the shape of that failure, because it is the whole point of this article. The standard control for business email compromise is the one every consultant repeats: if a payment instruction arrives by email, verify it through a different channel. That employee followed the advice. The second channel was the attack. The verification step was the con.
The lesson is not that verification does not work. It is that verification only works when you choose the channel, not when the requester does.
The counterexample: how Ferrari stopped the same attack in about nine seconds
In July 2024, an executive at Ferrari began receiving WhatsApp messages that appeared to come from CEO Benedetto Vigna. The number was not Vigna’s usual business mobile, but the profile photo was him. The messages described a major pending acquisition, instructed the executive to be ready to sign an NDA immediately, claimed Italy’s market regulator and the Milan stock exchange had already been informed, and asked for utmost discretion.
Then came a phone call. The cloned voice reproduced Vigna’s southern Italian accent well enough that the executive later called it convincing, but something in the intonation sounded slightly mechanical. So he said, in effect, sorry Benedetto, but I need to identify you, and asked what book Vigna had recommended to him a few days earlier. The call ended immediately. Ferrari lost nothing. A similar attempt on WPP chief executive Mark Read earlier that year also failed.
It is tempting to read that as a win for human detection. That is the wrong lesson, and it is the one most people take away. Noticing is not what saved the money. What saved the money was a challenge question the attacker could not answer, asked by someone who felt entitled to ask it of his own CEO. Detection created the pause. Process closed the door. The Arup employee also noticed something off, had no process to fall back on, and watched more convincing evidence overwrite his instinct.
What the federal data actually shows, and what it does not
The FBI’s Internet Crime Complaint Center published its 2025 Annual Report in spring 2026. It is the only large scale public dataset here not produced by a company selling a solution, so it is the one I use.
- IC3 logged 1,008,597 complaints in 2025, its highest ever, with reported losses of $20.877 billion, up 26 percent over 2024.
- Business email compromise was the second largest loss category: 24,768 complaints and $3,046,598,558 in losses, up from $2.77 billion in 2024.
- Cyber enabled fraud, meaning someone was persuaded rather than hacked, accounted for about 85 percent of all reported losses.
- For BEC specifically, 86 percent of stolen funds moved by wire transfer or ACH.
- IC3 tracked AI as a formal descriptor for the first time, logging 22,364 complaints and $893,346,472 in losses.
- Florida ranked third in the country in both complaint volume (71,843) and reported losses ($1,596,138,595).
The number I want to be honest about
Inside that AI descriptor, business email compromise with a reported AI nexus accounts for 135 complaints and $30,256,592 in losses. Against a $3.05 billion BEC total, that is about one percent.
There are two honest readings, and I will give you both. The first is that deepfake assisted fraud remains a small slice of the problem and you should not reorganize your company around one percent of reported BEC losses. That is fair and I will not pretend otherwise.
The second is that the descriptor only captures complaints where the victim knew to mention AI. IC3 says as much, noting for investment fraud that AI nexus losses of $632 million sit inside a category totaling over $8 billion because many victims never realize AI was involved. A controller who took a convincing phone call has no way to know a model produced the voice. I lean this way, but I am reading between the lines of a government report rather than citing a measured figure.
The disagreement does not change your decision. The control that stops an AI assisted BEC is the same control that stops an ordinary one, because a callback policy never asks whether the voice was synthesized. Two caveats most articles skip: these are reported crimes only, and under reporting here is significant, and the roughly $123,000 average loss per BEC complaint spans everything from a solo real estate closing to a city government. It is not a forecast for your business.
Why detection is a dead end
In 2023, researchers at University College London ran the study that should end this debate. They played genuine and synthetic audio to 529 people in English and Mandarin and asked them to pick out the fakes. The results were published in PLOS ONE under a title that does not require interpretation: Warning, humans cannot reliably detect speech deepfakes.
Listeners correctly identified the deepfakes 73 percent of the time. Training participants by showing them examples of synthetic speech first improved their accuracy by an average of 3.84 percent.
Three things about that finding matter more than the headline number.
- A 27 percent miss rate is not a control. If your protection against a fraudulent wire request is that somebody notices, you are accepting roughly a one in four chance of failure on each attempt, and the attacker gets to attempt as many times as he likes.
- The study participants knew they were being tested. They had been briefed that fakes were present and they were listening for them. Your controller at 4:40 on a Friday is not in that state of mind.
- Skepticism costs you in the other direction. In the same study, participants correctly identified genuine audio only 67.78 percent of the time. Train people to hunt for fakes and you also produce people who second guess real executives, which carries its own operational drag.
All of that was 2023 synthesis quality. The tooling has not gotten worse since.
Listen harder is a request for a skill humans do not possess and cannot be trained into. A verification process does not ask anyone to be a better listener.
What the attack actually requires from you
Strip away the technology and every one of these frauds needs four things at once:
- Urgency: a deadline you cannot independently verify.
- Secrecy: a plausible reason you must not discuss this with anyone else.
- Authority: an instruction from someone you do not normally question.
- A new destination for money: a new account, a changed wire instruction, or an unfamiliar payee.
Remove any one and the fraud collapses. None of the four requires you to determine whether a voice is real.
Secrecy is the most useful tell, and it is the common thread in both cases above. Arup: a confidential transaction. Ferrari: a secret acquisition, an NDA, utmost discretion. Legitimate transactions survive a second set of eyes. Fraudulent ones cannot, which is why every one of these scripts supplies a reason you must not get one. When urgency and confidentiality arrive in the same request, that combination is the signal. Not the voice.
The process that actually works
This costs almost nothing and gets skipped almost universally. Put it in writing, on one page, and have everyone who can move money sign it.
| What triggers it | What has to happen | Who signs off |
|---|---|---|
| Any wire or ACH above your dollar threshold | Callback to the number already in your own directory, never one supplied in the request | A second approver |
| Any change to a vendor bank account or wire instruction | A 24 hour hold plus a callback to the contact on file before the request arrived | AP plus one manager |
| Any request that is urgent and confidential at the same time | Full stop. Confidentiality is never a reason to skip verification | Anyone who receives it |
| Any voice or video request from an executive to move money | Challenge phrase, or hang up and call back on a known number. Never verify inside the channel the caller chose | The person who received the call |
| Any first payment to a brand new payee | Independent confirmation of the payee, the account, and the reason for the payment | A second approver |
Underneath that table sit three rules that are less about accounting than leadership.
A challenge phrase for anyone who can move money
The FBI has recommended for a while that families agree on a secret word to verify each other during a suspected voice cloning attempt. The logic transfers cleanly to a finance team. Agree on a phrase, rotate it quarterly, and never store it in email, your CRM, or a shared document sitting in the mailbox an attacker is most likely to compromise. Ferrari’s executive improvised one and it worked, but improvising under pressure is not a plan.
A standing no secret transactions policy, issued by the owner
Only you can create this, and it is the highest yield item in the article. Put it in writing and say it out loud in a meeting: I will never ask you to move money without telling anyone else, and any request claiming to come from me that demands secrecy is fraudulent by definition. No exceptions, including from me.
Your controller does not need better instincts. She needs permission to stop you.
Remove the penalty for being wrong
Say it explicitly and then live up to it: if you hold a legitimate wire of mine for thirty minutes to verify it, you will never hear a word about it from me. Without that, the math your employee runs at 4:40 on a Friday is not about deepfakes. It is about whether interrupting the boss is worth the risk. Every business I have watched lose money this way had a competent person who felt a flicker of doubt and did not feel free to act on it.
The technical controls, and their honest limits
These belong in the stack. They are also not what stops the phone call, so here is what each does and does not cover.
- SPF, DKIM and DMARC: email authentication at enforcement stops someone sending mail that appears to come from your actual domain. It does nothing about a lookalike domain, and nothing at all about a genuine mailbox that has been compromised. The same boundary applies to email filtering, which catches the payload and misses the pure social engineering.
- Phishing resistant MFA and conditional access: reduces mailbox takeover, which is how attackers learn your vendor names, your payment calendar, and how your CEO writes. Most BEC begins with reconnaissance inside a real inbox.
- Mailbox rule monitoring: attackers routinely create hidden forwarding and delete rules to stay invisible. Audit for them.
- Caller ID attestation: the STIR and SHAKEN framework reduces some spoofing on some calls. Do not build a control on top of it. Treat caller ID as decoration.
- Commercial deepfake detection tools: priced for enterprises, accuracy claims largely vendor reported, and the ones I have evaluated degrade badly on a compressed phone call, which is precisely the channel you care about. I do not currently recommend a small business buy one. Spend the money on the process instead.
If it already happened: the first 72 hours
The recovery odds are better than most owners assume, and they decay fast. In 2025 the IC3 Recovery Asset Team initiated the Financial Fraud Kill Chain on 3,900 incidents covering $1,163,919,846 in attempted theft and successfully froze $679,013,183, a 58 percent success rate.
That only happens if you move immediately.
- Call your bank now, not in the morning. Request a recall and ask what indemnification documents they need. Policies vary by institution, so learn yours before you need it.
- File at ic3.gov the same day with complete transaction details, including the receiving bank and account number. This is what feeds the kill chain.
- Call your local FBI field office directly.
- Notify your cyber insurance carrier and check whether social engineering fraud is actually covered. It is frequently a sublimit or separate endorsement rather than part of the base cyber policy, and owners tend to discover that distinction on the worst possible day.
- Preserve everything: call logs, voicemail, message threads, full email headers. Do not delete the fraudulent messages.
- Then investigate whether a mailbox was compromised, because the wire is often the last step rather than the first.
The 2025 IC3 report makes the reporting argument better than I can. In March 2025, a Missouri homebuyer lost over $1.3 million to a fraudulent title company wire and the recovery team froze the receiving account. In April, an Oregon city government sent over $6 million to that same account. Because of the earlier freeze, the receiving bank alerted the originating bank and the $6 million was recalled. Filing a report is not paperwork. It is how the next victim gets saved.
What this does not fix
Better you hear the limits from me than find them later.
- These controls slow legitimate payments. That is not a side effect, it is the mechanism. A 24 hour hold on vendor banking changes will irritate a real vendor eventually, and you should decide now that you accept that.
- No verification process prevents an attacker from sitting silently in a compromised mailbox for weeks first, learning how you talk and when you pay people.
- One override kills the policy. Pressure someone to skip the callback just this once and you have taught the whole team it is decorative, which is exactly what the attacker needs.
- A company with one bookkeeper cannot do internal dual authorization. The second approver may have to be you, your fractional CFO, or your outside accountant. Small does not mean exempt. It means the second set of eyes lives somewhere else.
- None of this addresses reputational deepfakes, meaning a fabricated video of you saying something you never said. That is a real and growing problem, it is a different problem, and it needs a different response.
My own interest in this, stated plainly
Harmony MSP sells managed IT and security services to small businesses, law firms, and medical and dental practices. I have a commercial interest in you believing that email authentication, conditional access, mailbox monitoring and awareness training matter. They do, and we sell them.
But the three things that would have stopped both cases in this article are a callback policy, a challenge phrase, and an owner saying out loud that no secret transaction is ever legitimate. None of those require a vendor. You can write all three this afternoon without spending a dollar with me or anyone else, which is exactly why I put them ahead of the technical section rather than behind it. If you take one thing from this post, I would rather it be the policy than the product.
The part nobody wants to hear
The uncomfortable truth about deepfake enabled fraud is that the fix is not technical, expensive, or exciting. It is a decision by the owner to make verification normal, to make hesitation safe, and to accept a little friction in exchange for not wiring six figures to a stranger who sounds like family.
The voice on the phone will keep getting better. Your process does not have to.
If you want a second set of eyes on how payment requests actually move through your business, or help writing a verification policy your team will follow rather than ignore, I am glad to walk through it with you. Harmony MSP is based in Lake Mary and works with small businesses across Central Florida. You can reach us at (407) 720-6540. No pitch required, and if the answer is that you already have this covered, I will tell you that too.
Sources
- FBI Internet Crime Complaint Center, 2025 Annual Report: ic3.gov
- Mai, Bray, Davies and Griffin, Warning: Humans cannot reliably detect speech deepfakes, PLOS ONE, 2023: journals.plos.org
- CNN Business, Arup revealed as victim of $25 million deepfake scam, May 2024: cnn.com
- Fortune and Bloomberg, Ferrari exec foils deepfake attempt, July 2024: fortune.com
- MIT Sloan Management Review, How Ferrari Hit the Brakes on a Deepfake CEO: sloanreview.mit.edu
- FinCEN Alert FIN-2024-Alert004, Fraud Schemes Involving Deepfake Media Targeting Financial Institutions, November 2024: fincen.gov
- FBI IC3 Public Service Announcement, Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, December 2024: ic3.gov
- UCL News, Humans unable to detect over a quarter of deepfake speech samples: ucl.ac.uk



