Judge the request, not the voice. Deepfake scams ask for money, changed bank details, passwords or files, with urgency and secrecy, often through a new channel such as WhatsApp or a surprise video call. Spot them by rule: hang up, call back on a number you already hold, ask for a pre-agreed code word, and never act on the call alone.
Listening for glitches is the weak part of any defence. Cloned voices and live video fakes keep improving, and a scammer needs very little material: in 2024 OpenAI said its own Voice Engine could generate speech closely resembling a speaker from a single 15-second sample, and encouraged phasing out voice-based authentication for bank accounts and other sensitive information. So the protection that works is process. A call-back rule and a code word cost nothing and don't depend on anyone's ear.
How a cloned voice or fake video call reaches a small firm
The technology is new; the scripts aren't. Almost every attempt follows one of five patterns, each a version of an old fraud with a more convincing voice attached.
- The boss on a new number. A WhatsApp message from "the owner", who is travelling or in a meeting, followed by a voice note in their voice: an urgent payment, a batch of gift cards, a supplier who must be paid today.
- The video call full of familiar faces. An invitation to a "confidential" call about a deal. The faces and voices match senior colleagues. The ask comes at the end, framed as already agreed.
- The supplier with new bank details. An email announcing a change of bank, then a friendly call or voice note from the "accounts manager" to make it feel verified.
- The client who wants their files. A caller who sounds exactly like a long-standing client asks for copies of accounts or ID documents to go to a new email address.
- You, impersonated to your customers. A voice note "from you" tells a customer your bank has changed and asks for the deposit to go to new details.
Two reported cases show both endings. In 2024 the engineering firm Arup confirmed that "false voices and images were used" after a member of staff, first contacted about a "confidential transaction", joined a video call with a faked chief financial officer and other faked colleagues, then sent about $25 million to five bank accounts. It came to light when the employee checked with head office afterwards. The same year, a Ferrari executive received WhatsApp messages from an unfamiliar number carrying the chief executive's photo, then a call in a cloned version of his voice about a secret acquisition. The executive noticed slight inconsistencies in tone and asked for the title of a book the chief executive had recommended days earlier. The caller couldn't answer and hung up.
The difference between those outcomes wasn't better eyesight. One person had a check they could use in the moment; the other was pressed into acting before checking. A small firm is a far easier target than either company, because one person often holds both the banking app and the authority to use it.
Warning signs that matter more than glitches
Train people to notice the shape of the request. These signs hold whatever the quality of the fake:
| Sign | How it shows up | What to do |
|---|---|---|
| Urgency plus secrecy | "Needs doing before 5. Keep it between us, the deal isn't public yet." | Slow down. Secrecy exists to stop you checking with anyone. |
| A new or unusual channel | The owner suddenly on WhatsApp from an unknown number; a video call from a personal account | Call back on the number you already hold |
| Skipping the normal process | "Don't bother the finance director, I've approved it." | The process exists for exactly this moment |
| New bank details | A subcontractor has "changed banks" halfway through a project | Run the payment-change check below |
| Can't be verified | Camera "broken", line "bad", can't take a call-back right now | Treat it as unverified: no action |
| Unusual payment method | Gift cards, cryptocurrency, a personal account "just this once" | Always no |
| Audio or video oddities | Flat intonation, lips slightly out of sync, a face that smears when a hand passes it | Useful when you spot them; their absence proves nothing |
Deepfake calls often arrive alongside a fake email or a compromised mailbox, so the email side of staff training matters too; training staff to spot AI-written phishing emails covers that half.
Checks to run while the call is still live
Most staff freeze because ending a call with "the boss" feels rude. Give them words to say, written down, so ending the call becomes following a rule rather than making an accusation. An illustrative script for whoever answers:
"I'm going to hang up and ring you straight back on your usual number.
It's our rule for any payment or bank change, and it applies to everyone."
If they push back:
"I understand it's urgent. I still can't act until I've called back.
If it really can't wait five minutes, I'll ask [second person] to help."
If it's a video call:
"Let's pick this up by phone. I'll call your mobile now."
Beyond the call-back, three checks help in the moment:
- Ask something only the real person knows and nobody has written down. The Ferrari executive's book question worked because the answer wasn't public. "What did we discuss at Tuesday's site meeting?" works; "What's the project name?" doesn't, because it's in the email thread the scammer may have read.
- Ask for the code word. See the protocol below. A real director says it without fuss; a scammer stalls, gets angry or changes the subject.
- Don't feed them details. "Is this about the warehouse extension job?" hands the scammer a story. Let them supply the specifics, and notice when they can't.
Some security teams suggest asking a video caller to turn side-on or pass a hand across their face, because older face-swap tools blurred at those moments. Treat that as a bonus, never as the test. Newer tools cope better, and a pass tells you nothing.
The verification protocol to copy
This is the core of the defence. Copy it, fill in the brackets, print it for everyone who can pay money or send files, and put a copy next to the banking login.
[BUSINESS NAME]: VERIFICATION RULES FOR PAYMENTS AND SENSITIVE REQUESTS
Applies to: anyone who can pay money, change bank details, share
passwords or send client files. Reviewed: [month, year]
1. CALL-BACK RULE
Any request to move money, change bank details, share login details
or send client files that arrives by phone, video call, voice note,
text or chat app is confirmed by calling the person back on the
number held in [the office contacts list / accounting system].
Never use a number given in the request or its email signature.
No answer = no action, however urgent it sounds.
2. CODE WORD
Directors and anyone who approves payments share a code word agreed
face to face. It is never written in email, chat or the calendar.
An urgent request from a "director" must include the code word.
A wrong answer, a refusal or "I haven't got time" ends the call.
If the code word is ever said on a call, change it that week.
3. PAYMENT-CHANGE CHECK (suppliers, subcontractors, clients)
a. Never change bank details because of an email, letter, call or
message alone.
b. Call the supplier on the number in the original contract or a
past invoice and speak to their accounts team.
c. A second person reviews the call note and approves the change.
d. Hold the first payment to new details for [2 working days].
e. For amounts over [$5,000], send a small test payment first and
ask the supplier, on the known number, to confirm the amount.
4. TWO-PERSON RULE
Payments over [$2,000], and any payment to a new payee, need a
second person's approval in the banking app.
5. PERMISSION TO SAY NO
Nobody is ever in trouble for checking. The owner will never ask
anyone to skip these steps; any message that does is a scam.
6. REPORT IT
Tell [first name] about any request that fails a check, even if no
money moved, so everyone else can be warned the same day.
Each rule closes a specific gap. The call-back number comes from your own records because a scammer controls every number in the message, including the signature. The code word is never written down because a compromised mailbox or shared chat would reveal it. The hold on new bank details exists because most payment-change fraud relies on money moving before anyone thinks to phone the supplier. Rule five matters most in a small firm: staff need the owner's advance permission to be awkward with the owner. For the wider approval process around payment runs, AI accounts payable approvals shows where these checks sit.
Putting the protocol in place in one week
- Map who can move money (30 minutes). List everyone with banking access, what they can approve alone, and which systems hold supplier bank details: the banking app, the accounting software, any payroll service.
- Build the call-back list (1 hour). Take phone numbers for staff, key clients and your 20 largest suppliers from contracts and past invoices, not recent emails. Store them in the accounting system or a locked shared file.
- Agree code words (15 minutes, in person). Pick something not guessable from social media: not a pet, child or football team. Nothing goes in writing.
- Set the bank-side controls (30-60 minutes). Turn on dual approval if your business account supports it, set payment limits per user, and switch on alerts for new payees. If your bank checks a new payee's name against the account, treat a "no match" warning as a stop sign, never a formality.
- Add the customer notice to quotes and invoices (20 minutes). Wording is in the customer section below.
- Brief everyone (30 minutes), then drill within a month. Walk through the script and protocol, then test it as described further down.
That's about four hours in total. The second step takes longest and matters most: a call-back rule is only as good as the number you call.
A Friday-afternoon request at an engineering consultancy
Here's the protocol working in a 14-person engineering consultancy, walked through as an illustration. The accounts assistant can pay suppliers up to $2,000 alone; anything larger needs a director's approval in the banking app.
- 4:40pm. A WhatsApp message from an unknown number, with the managing director's photo: "Hi [first name], new number, phone died. Need a favour before I board." Then a 20-second voice note in the managing director's voice: the steel fabricator on a current project must get a $38,400 deposit today or loses its slot; their accounts team will email new bank details.
- 4:44pm. An email arrives from an address one letter different from the fabricator's real domain, with bank details on a letterhead copied from a past invoice.
- 4:46pm. The assistant follows rule 1 and calls the managing director's number from the contacts list. No answer; plausible if boarding. Under the rule, no answer means no action.
- 4:48pm. The assistant replies on WhatsApp asking for the code word. The reply: "No time for that, just do it please, I'll explain Monday." That fails rule 2.
- 4:52pm. The assistant calls the fabricator on the number from the purchase order. Their accounts team has no record of changed details and hasn't requested a deposit.
- 4:55pm. The assistant reports it under rule 6. The other director warns the team and the fabricator, whose letterhead is being misused.
The sums: fifteen minutes of checking against a $38,400 loss. Even if the request had been real, the cost of waiting was a deposit paid on Monday morning. Look too at what the scammer got right: a real supplier, a real project, a plausible amount, the owner's real voice. Only the process was out of their reach.
When the voice asks for files or a login code, not money
Not every deepfake is after a payment. Client files and account access are worth money too, and the requests sound more innocent, so people check them less.
Picture a six-person accountancy practice. A caller who sounds exactly like a long-standing client rings the junior who handles her file: she's "locked out of her email", needs last year's accounts and a copy of her passport for a mortgage application today, and asks for them to go to a new personal address. Every detail of the story is plausible, and it would take thirty seconds to send. Under the protocol, the junior says she'll call back, rings the client's number from the practice management system, and reaches the real client, who knows nothing about it. Had the files gone, the practice would have handed an identity thief exactly the documents needed to open accounts in the client's name.
The login-code version is shorter and more dangerous. A "director" on a video call says the system has logged them out and asks a colleague to read out the six-digit code that has just arrived on the colleague's phone. That code is often the last barrier protecting the colleague's own account. Add one line to the protocol and to the briefing:
7. CODES AND FILES
We never read out, forward or type in a one-time login code for
anyone else, whoever asks and however senior they sound.
Client documents go only to contact details already on file.
A request to use new contact details gets a call-back first.
If staff send files by email, a data-loss-prevention rule can add a second net by flagging messages that carry identity documents to unfamiliar addresses. It's no substitute for the call-back, but it catches the tired Friday-afternoon slip the protocol relies on people not making.
Drilling the rule without embarrassing anyone
A protocol nobody has practised fails under pressure. Run a drill a few weeks after the briefing, announced in general terms ("we'll test the payment rules sometime this month") so nobody feels ambushed.
A simple drill: a director records a voice note from a personal phone asking the person who pays suppliers to send "$1,850 to a new supplier today, details to follow". Score three things: did they call back on a known number, did they ask for the code word, and did they report it?
Illustrative results from a first drill in a nine-person architect practice:
- Two of the three people with banking access called back on the contacts-list number. Pass.
- The third replied to the voice note: "Is this really you?" That's the most common failure. A scammer simply says yes, so asking the suspicious sender to confirm themselves checks nothing.
- Nobody reported it, because it "obviously wasn't real". Rule 6 exists so that one person's obvious fake becomes everyone's warning.
Two other failures turn up often enough to check for. A code word saved in the shared calendar ("Code word for payments: Juniper") is readable by anyone who gets into one mailbox, and a code word taken from the owner's public life, such as a dog's name that appears in the firm's social posts, is guessable. Change either on the spot. Then rerun the drill a quarter later with a different channel, such as a video call invitation instead of a voice note.
Stopping scammers from posing as you to your customers
Deepfakes also point outwards. Take a kitchen fitter who takes a 40% deposit on an $18,000 kitchen. A scammer who has seen the quote, perhaps through a hacked customer email account, sends the customer a voice note in the fitter's cloned voice: "Hi [first name], our bank's changed, can you send the $7,200 deposit to these new details?" The customer, who has heard the fitter's voice on the phone a dozen times, pays. The business has done nothing wrong, and still loses a deposit, a customer and a week of goodwill.
The defence is a notice customers see before they ever pay. A filled-in version for the bottom of every quote and invoice:
PAYING US SAFELY
Our bank details are printed on this quote and will not change during
your project. We will never send new bank details by text, WhatsApp,
voice note or email. If you receive a message asking you to pay a
different account, even if it sounds like us, do not pay: call us on
[office number, as shown on our website] first.
Say the same thing out loud when you hand over the quote. A customer who has heard "we never change bank details by message" is far more likely to ring before paying. It costs one sentence and protects the business's name as much as the customer's money.
The first hour after money has gone
If a payment has already gone to a scammer, speed matters more than anything else.
- Call your bank's fraud line immediately, using the number on its website or the back of a card. Ask it to try to recall the payment and alert the receiving bank. Minutes can make a difference.
- Keep everything. Voice notes, call logs, the WhatsApp thread, the email with its full headers. Don't delete the chat in embarrassment; it's evidence.
- Report it to the police through the fraud reporting route in your country, and note the reference number for your bank and insurer.
- Tell your insurer or broker the same day. Policies usually require prompt notice, and cover for being tricked into paying varies a lot between policies; whether cyber insurance covers AI incidents explains what to ask.
- Check the mailbox behind it. If the scam used real email threads, change the password, sign out all sessions, and look for forwarding rules the attacker may have set up.
- Warn the people whose names were used, such as the supplier or client, so they can alert their own customers.
Afterwards, write down what happened in the order it happened and which rule would have stopped it, without blame, and change the protocol if a gap showed. An AI incident response plan gives that review a template, and catching duplicate invoices and payment fraud covers the checks that run on your payment records the rest of the year.
Deepfake fraud questions from small-business owners
Can AI clone my voice from my voicemail greeting or social videos?
Assume it can. In 2024 OpenAI said its Voice Engine could generate speech closely resembling a speaker from a single 15-second sample, and a voicemail greeting, a podcast or a short social video supplies that much. You can't take all your audio offline, so the protection has to come from checking requests rather than keeping your voice secret.
Are there apps that detect deepfake calls automatically?
Detection products exist, but fakes and detectors improve in turn, and none replaces a rule that works whatever the technology does. For a small business, a call-back on a known number and a code word catch the scam for free. If you trial a detection tool, treat it as a second layer and keep the manual rule in place.
What if a real client asks us to pay a refund to new bank details?
Use the same payment-change check you use for suppliers. Call the client on the number you hold on file, not one in the request, confirm the new details verbally, have a second person approve, and hold the payment briefly. Genuine clients accept a short delay; a fraudster pretending to be the client usually objects to it.
Should the owner stop posting videos to cut the risk?
Not usually. Less public audio gives scammers less material, but the business probably needs the visibility, and a scammer can find enough elsewhere. It's more useful to stop publishing the details scammers build stories from, such as who approves payments, the owner's travel dates, or which suppliers you're working with right now.
Further reads
- AI Security Risks for Small Businesses and How to Close Them — The wider set of AI security risks and how to close them.
- Is It Safe to Connect AI Tools to Your Business Bank Account? — Before any AI tool touches the account these scams target.
- AI Security Checklist Before Connecting Tools to Email and Files — Lock down the mailboxes that deepfake calls often follow up.
- How to Share AI Tool Logins Safely With a Password Manager — Keep shared logins out of the chats scammers ask for.
- What Is Data Loss Prevention, and Does a Small Business Need It? — Stop client files leaving when someone is fooled into sending them.
- Microsoft 365 Business Premium vs Standard for AI Security — Which plan adds the account protections behind this protocol.
- When Not to Use AI in Your Business: 9 Tasks to Keep Human — Nine tasks a person should always decide, what AI can safely prepare for each, and a three-question score for any task that isn't on the list.
- How to Deflect Password Resets and Routine Requests With AI — Cut password and routine IT tickets: self-service reset licensing, which requests are safe to deflect, bot guardrails, sample chats and honest metrics.
- How Conveyancers Use AI to Cut Admin on Each Transaction — Stage-by-stage admin savings for a conveyancing file, a title-summary prompt with sample output, chaser wording and the tasks AI must never touch.
- Which Legal Tasks Should a Small Firm Never Hand to AI? — A four-question test for legal AI risks, the seven jobs that stay with a named lawyer, and wording to put the line in your firm's AI policy.
- Charity AI Risks: Data Protection, Deepfakes, and Donor Trust — Three risk areas for charities using AI, with real cases, the controls that work for a small team, and a filled-in one-page risk register.
- How to Handle a Fake or Unfair Review With AI's Help — Sort fake from unfair, use AI to check records and map the review to Google's policies, report it properly, and reply without making it worse.
- How to Make Marketing Videos With AI Without Being on Camera — Four faceless video formats, a 60-second script structure, AI voices and avatars priced, and three small businesses' videos built without anyone on camera.
- Should You Use an AI Avatar as Your Business Spokesperson? — Stock avatar, digital twin or you on camera: a scorecard, real tool prices, consent wording for staff, and a low-risk way to trial an AI presenter.
- How to Spot Fake AI Apps and Risky Browser Extensions — Real cases of fake ChatGPT downloads and chat-stealing extensions, plus a 60-second install check and a browser audit for small teams.
- What Is Prompt Injection and Should a Small Business Worry? — How hidden instructions in emails, web pages and CVs hijack AI assistants, a five-minute exposure check, and the controls that work without an IT team.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: CFO Dive's report on the Arup deepfake fraud (citing Arup's statement to the Financial Times); MIT Sloan Management Review, 'How Ferrari Hit the Brakes on a Deepfake CEO'; OpenAI, 'Navigating the challenges and opportunities of synthetic voices' (2024).