Industries

Ensure your unique data and process requirements are being met with IT solutions built on deep domain experience and expertise.

Company

At Coretelligent, we’re redefining the essence of IT services to emphasize true partnership and business alignment.

Insights

Get our perspective on the connections between technology and business and how they affect you.

The Deepfake CFO Problem: What Voice-Cloning Fraud Means for Your Approval Processes

In this post:

Your finance team just got a video call from the CFO. The face looks right. The voice sounds right. The request is urgent: approve a wire transfer before the market closes. Nothing about the call raises a flag, because nothing about the call is real.

This is voice cloning fraud, and it already cost one engineering firm $25.6 million. Arup lost the money across 15 separate wire transfers after a video call where every participant, including the CFO, was AI-generated. The employee on that call did not fail a training module. He followed a process that was never built to survive this kind of attack.

2025 US losses

$1.1B

Audio needed to clone a voice

3 sec

Human deepfake detection rate

~25%

Deepfake fraud losses: 2024 $360M, 2025 $1.1B.

Voice Cloning Fraud Has Moved From Rare to Routine

Deepfake-based fraud losses in the United States hit $1.1 billion in 2025. That is up from $360 million the year before, a threefold jump in a single year. The growth curve is not slowing down, and it is not limited to Fortune 500 targets. Any company with a finance team and a wire transfer process is a candidate.

What makes voice cloning fraud different from older scams is the barrier to entry. A convincing voice clone needs as little as three seconds of audio to reach about 85 percent accuracy. Every earnings call, podcast appearance, and conference keynote your executives have ever recorded is sitting in public view. That is training data, and attackers know it.

The FBI took this seriously enough to add a dedicated AI-fraud section to its 2026 Internet Crime Report. That is a signal to every finance and security leader. Regulators no longer treat voice cloning fraud as a fringe risk. They treat it as an expected threat that companies should already be defending against.

How Voice Cloning Fraud Actually Works

Attackers do not start with the phone call. They start with research. LinkedIn profiles, SEC filings, and company org charts tell them exactly who holds approval authority over a wire transfer. Press releases about acquisitions or partnerships supply a believable reason for an urgent payment.

Once the target and the pretext are set, the attacker harvests audio and video from public sources. A webinar recording, a media interview, or an internal town hall posted online without much thought becomes raw material for a synthetic voice. The attacker then builds pressure into the request. Urgency, secrecy, and an appeal to authority all show up in nearly every case.

The Arup incident shows how far this has gone. The attack was not a spoofed email or a recorded voicemail. It was a live, real-time video conference with multiple synthetic participants speaking naturally to one real employee. That employee suspected phishing at first. The live call, with synchronized faces and convincing voices, overcame his doubt anyway.

Why Your Current Approval Process Cannot Catch This

Most wire transfer approval processes rely on three checks: does the request come from a known number, does the voice sound familiar, and does a second person confirm it on a call. Voice cloning fraud defeats all three at once.

Caller ID can be spoofed cheaply. A cloned voice sounds exactly like the executive it imitates, so a callback to the same channel proves nothing. Even the four-eyes principle fails when both reviewers are on the same manipulated video call, watching multiple fake executives approve the same transaction. The problem is not that employees are careless. The problem is that the verification method itself has been broken.

This matters because annual security awareness training has shown limited effect on voice cloning susceptibility specifically. The training targets ignorance. The attack targets authority compliance, a psychological trigger that does not respond to a slide deck. Coretelligent’s breakdown of social engineering and the human element covers why this gap persists even at companies with mature security programs.

Rebuilding Approval Processes to Survive Voice Cloning Fraud

The fix is not a better ear for spotting a fake voice. Humans correctly identify high-quality deepfake video only about a quarter of the time, so the fix has to live in the process itself.

Out-of-Band Verification

Any request for a wire transfer, especially one that carries urgency or secrecy, should require confirmation through a channel that was never part of the original call. That means calling the executive back on a pre-registered number stored internally, not the number that appeared on the incoming call. It also means never confirming a transfer through the same video platform the request arrived on.

Dual Authorization With Independent Channels

A single call, no matter how convincing, should never be enough to move money. Require two separate employees to confirm the request through two separate, independently verified channels before execution. This closes the gap that the Arup case exposed, where every reviewer was inside the same fabricated meeting.

Code Words and Time Delays

A pre-agreed passphrase, established in person and never sent digitally, gives your team something a cloned voice cannot fake. Pair that with a mandatory waiting period, four to eight hours is common, on any transfer that falls outside normal business patterns. Time pressure is the attacker’s main tool, so removing it removes most of the leverage.

Wire transfer approval process, before and after hardening against voice cloning fraud Left column shows the vulnerable process: known caller ID, familiar voice, same-channel confirmation. Right column shows the hardened process: out-of-band callback, dual independent channels, code word plus time delay. Vulnerable process Hardened process Caller ID match Spoofed cheaply Familiar voice Cloned from 3 sec of audio Second reviewer confirms Same call, same fake meeting Wire approved Funds gone Out-of-band callback Pre-registered number, not the call Dual independent channels Two people, two separate checks Code word + time delay 4-8hr hold on unusual transfers Wire approved Verified, funds safe breaks all 3 checks at once

Training Finance Teams to Question the Voice on the Call

Awareness training still matters, but it needs a different focus. Employees should hear, explicitly, that a familiar voice and a live video feed are no longer proof of anything. The goal is not to make people paranoid. The goal is to make pausing and verifying the default response to urgency, not an exception.

Run tabletop exercises that simulate a deepfake call to your accounts payable team. Test whether your escalation path actually holds under pressure. Coretelligent’s guide to incident response and recovery for phishing and BEC attacks outlines what to do in the first hour after a fraudulent transfer, including which numbers to call and how fast a bank can act to freeze funds.

Remove blame from the equation entirely. Voice cloning fraud is convincing enough that a well-trained employee can still fall for it. A blame culture only teaches people to hide mistakes instead of reporting them quickly, and speed is the one advantage your team has after money starts moving.

What Regulators and Insurers Expect Now

Cyber insurance policies do not automatically cover voice cloning fraud losses. Many carriers draw a hard line between classic cyberattacks and social engineering fraud, and deepfake incidents often sit awkwardly between the two categories. Review your policy specifically for AI-enabled fraud coverage, and negotiate a dedicated add-on if the current language leaves a gap.

Insurers are also starting to ask for proof of prevention before they extend favorable terms. Companies that can show dual authorization, out-of-band verification, and documented training get better rates and fewer disputed claims. That connects directly to the FBI’s decision to formally track AI fraud as its own reporting category. Regulators and underwriters are both signaling that “we didn’t know this was a risk” no longer holds up as a defense.

Coretelligent’s overview of AI-powered phishing and the 2025 threat landscape walks through how boards and audit committees are starting to ask management pointed questions about exactly this exposure.

Where This Leaves Your Approval Process

Voice cloning fraud is not a future risk to plan for eventually. It is an active threat with a documented eight-figure loss already on the record, and the technology behind it keeps getting cheaper and more convincing. The Arup case proved that trust in what a team sees and hears on a call is no longer a reliable control.

Start by asking one direct question about your own process. Would a wire transfer still get approved if the CFO on that call was not real? If the honest answer is anything other than no, that gap is where your next review should begin. Out-of-band verification, dual authorization, and a code word your team never wrote down anywhere digital will do more to stop voice cloning fraud than any amount of training aimed at spotting a fake voice by ear.

Your Next Read

Cyber-Enabled Fraud Is Outpacing Ransomware as the Threat Boards Should Actually Fear in 2026

How can we help you?

Our engineers provide help desk support and a whole lot more.