Deepfake Voice Calls: When "the CEO" Phones Finance
AI can now copy a voice from a few seconds of audio. Here is how attackers use cloned voices and faked video calls to authorise payments, and the verification habits that defeat them.

For years the advice for a suspicious payment email was simple: pick up the phone and check. Attackers have noticed. With AI voice cloning, the voice on the other end of that call can now be fake too.
What has changed
Voice cloning tools can produce a convincing imitation of a person from a short recording, and executives leave plenty of those behind: interviews, conference talks, podcasts, videos on social media. Video can be faked as well. In early 2024, a finance employee at the engineering firm Arup in Hong Kong was persuaded to transfer around 25 million US dollars after a video call in which the company's chief financial officer and other colleagues appeared. None of them were real.
The technology is not the clever part. The script is. These calls follow the same pattern as every other payment fraud: authority, urgency and secrecy.
How a deepfake call usually unfolds
- A setup message. An email or WhatsApp message from "the CEO" warns that a confidential deal is under way and a call is coming.
- The call. A familiar voice, sometimes a familiar face, explains the deal and asks for a transfer today.
- The pressure. The deal will collapse if the money is late. Nobody else can know yet. The caller is about to board a flight.
- The follow-up. Payment details arrive by email "as discussed", making the request feel already approved.
Warning signs: a new or withheld number, a call that you did not arrange, a request to bypass the normal approval process, insistence on secrecy, and a reason why you cannot call back. Audio may sound slightly flat, or the caller may avoid unexpected questions.
Defences that do not depend on spotting the fake
The quality of these fakes will keep improving, so the defence cannot be "listen carefully". It has to be a process that a perfect fake still cannot pass.
- Call back on a known number. End the call and ring the person on the number in your directory. An attacker cannot answer the real executive's phone.
- Agree a verification phrase for payment requests among finance and senior leaders, and never say it over email or chat.
- Keep dual approval for large payments, with no exception for requests that claim to come from the top.
- Ask something only the real person would know, not something that can be found online.
- Make it safe to say no. Leaders should state publicly that they will never ask anyone to bypass payment controls, and that checking will always be welcomed.
A simple rule for any urgent payment: if the request arrived through a channel you did not start, confirm it through a channel you did.
Preparing your people
Staff who have never heard of voice cloning have no reason to doubt a familiar voice. A short briefing, repeated regularly, changes that. With CyberWatch AI an organization can run realistic practice attacks that follow this same pressure pattern, train the teams who hold payment authority, and measure whether the habit of verifying is taking hold across the organization.


