Deepfake voice scams—calls from AI-generated copies of executives requesting urgent wire transfers—are costing businesses hundreds of millions annually. The FBI received over 22,000 reports of AI-generated voice or video scams in 2025, with reported losses approaching $893 million, making this the fastest-growing financial fraud threat to companies of any size. Finance teams no longer can trust voice or video alone to confirm payment requests.
The good news: proven defenses already exist and require no specialized software. Out-of-band callback verification, pre-agreed codes, and dual-approval workflows block these scams reliably, even when the deepfake is convincing enough to fool visual and audio inspection. Implementation takes hours, not months.
Table of Contents
- How realistic are deepfake CEO calls?
- Why seeing and hearing isn't enough
- The defenses that actually stop deepfakes
- How to implement verification in hours, not months
- Frequently Asked Questions
How realistic are deepfake CEO calls?
The technical barrier is lower than most businesses assume. Commercial AI voice-cloning tools can generate convincing synthetic speech from as little as three seconds of clear audio, meaning a scammer needs only a brief clip from a company earnings call, press interview, or recorded message to impersonate an executive convincingly. The voice carries natural inflection, emotion, and the subtle speech patterns that would normally signal authenticity.
Real incidents prove the risk is not hypothetical. One documented case involved a company CFO who authorized a $243,000 wire transfer after receiving a call in their CEO's voice, later confirmed to be an AI deepfake. In a more severe incident, a finance employee transferred $25.6 million across 15 separate transactions after a deepfake video conference where all participants, including the apparent CFO, were AI-generated. These employees were not careless; they were defeated by technology that matched both audio and visual cues they trusted.
Why seeing and hearing isn't enough
Many companies still rely on visual or audio confirmation to vet payment requests. This approach has a fatal flaw: video verification alone is no longer reliable—scammers can generate deepfake video of executives convincingly enough to pass real-time visual inspection during calls. A finance employee watching what appears to be a live video call with their CFO—one that includes a face match, consistent gestures, and a real-time video feed—has no practical way to detect the deepfake during the call itself.
The attack also exploits psychology. Scammers time deepfake calls outside business hours to reduce verification likelihood and create urgency, targeting finance departments specifically for wire transfers and vendor payment changes. A finance employee alone on a Sunday evening, receiving an urgent message from their CEO's number with a video call pending, faces enormous social pressure to act fast. Speed is the weapon; verification is the only defense.
The defenses that actually stop deepfakes
Three layers of controls—callback verification, pre-agreed codes, and dual approval—work regardless of how convincing the initial deepfake contact is. The most effective single control is an out-of-band callback to a pre-established number (never the number initiating the request) for any payment above a threshold or vendor banking detail change. If a finance employee receives a payment request via a call or video, they hang up and immediately call their CEO or CFO on a number they know independently—from the company directory, from memory, from a previous email. The scammer cannot intercept this callback or know the real number in advance. Pre-agreed verification codes unknown to recorded communications or written records create an authentication factor deepfake AI cannot access, stopping scams even when voice and video are spoofed.
The code can be a simple phrase, a number, or an acronym that only finance leadership and payment approvers know. It never appears in emails, voicemails, or scripts the scammer can harvest. Even if a deepfake convincingly demands a wire transfer with perfect audio and video, a simple "What's the code?" stops it cold. Dual-approval structures requiring separate requestor, approver, and executor roles prevent a single compromised employee from completing payment fraud, regardless of how convincing the initial deepfake contact is. One person receives and documents the request, a second person approves it (using callback or code verification), and a third person executes the transfer. No single deepfake call can manipulate all three.
How to implement verification in hours, not months
These defenses require no specialized software and integrate into existing payment workflows. The documented defenses that work—callback verification, pre-agreed codes, and dual approval—require no specialized software and can be implemented in existing processes within hours. Start with a policy that any payment request above a set threshold (for most companies, $10,000 to $50,000) triggers callback verification to a known number. Brief finance staff on the protocol: a deepfake call comes in, they say "I'll get back to you," hang up, and call the requestor through an independent channel.
Next, establish a short verification code or phrase known only to finance leadership and share it with the team as a standard question for any high-value or vendor-change request. Finally, document your approval chain so that no single person can initiate and complete a wire transfer alone. These three steps require a policy memo, a team meeting, and a code stored in a secure location—not a software deployment. Test the process once with a dry run: simulate a payment request during low-stakes conditions, walk through the callback and code verification, and confirm the workflow catches a fake. Adjust timing or communication if needed, then go live.
Frequently Asked Questions
Can deepfakes fool video calls as well as voice calls?
Yes. Scammers can now generate convincing deepfake video of executives during real-time video calls, so visual confirmation alone is not a reliable defense for payment verification.
Do I need to buy new software to defend against deepfakes?
No. Callback verification to a pre-established number, pre-agreed authentication codes, and dual-approval workflows stop deepfakes and require only policy and communication, not new tools.
What's a realistic threshold for callback verification?
Most companies should require callback verification for any wire transfer, vendor payment change, or banking detail modification above $10,000 to $50,000, depending on company size and risk tolerance.
You Might Also Like
- On Q Financial Data Breach Settlement: How the Estimated $50 Payment Works
- Lemonade Privacy Breach Settlement: Can Class Members Get Monitoring Without a Cash Claim?
- Lemonade Insurance Data Breach: When Can You Activate Settlement Credit Monitoring?