Cybersecurity

The Deepfake CEO Scam: Voice Cloning and Business Email Compromise

The phone rings. It’s your boss’s voice — same tone, same rush — asking you to move money or send a file right now, before a deadline. Except it isn’t your boss. It’s a criminal playing a cloned voice. This is where business email compromise is heading, and it’s already here.

For years, fraud like this came by email: a fake message from the “CEO” asking for a wire. Email filters got better at catching those. So attackers changed lanes. A voice call skips the filter and goes straight at the one thing no software fully protects — a person’s trust in a familiar voice.

How voice cloning works now

The barrier has dropped fast. A few seconds of someone’s speech — from a webinar, a podcast, a social clip, even a voicemail greeting — can be enough to build a convincing copy. Cheap tools do the rest. The attacker doesn’t need to write code. They need a target, a short clip, and a story that feels urgent.

Why these calls work

They aim at how people are wired, not at your firewall. Staff are trained to help the boss quickly. A cloned voice adds pressure — stress, deadlines, a favor that “can’t wait.” Criminals time it for a Friday afternoon or the day before a holiday, when there’s less chance to check. Our ears also fill in gaps, so a slightly off voice still passes.

What the numbers show

In its 2025 report, the FBI’s Internet Crime Complaint Center tied billions of dollars in losses to business email compromise, and flagged AI-enabled scams as a fast-growing risk. Voice is a natural next step: it carries the same con — a trusted leader, an urgent payment — with a stronger hook.

How to defend without buying a gadget

There’s no reliable “deepfake detector” for a live call, so the defense is a habit, not a device.

Verify on a second channel. Any urgent money or data request gets confirmed a different way — a call back on a known internal number, a message in Teams. Never use the number the caller gives you.

Use a code word. Agree on a private phrase for money moves, known only to the few people who make them.

Slow the money down. Build a rule that big or rushed transfers wait for a second person to approve. Scammers depend on speed and panic; a required pause breaks both.

Train the roles that get targeted. Finance, HR, IT, and executive assistants should practice these calls, not just read about them. Strong cybersecurity today means protecting people’s judgment, not only the network.

What this means for your business

A familiar voice is no longer proof of who’s calling. Treat any urgent request for money or data as unverified until you confirm it on a separate, known channel. A code word for payments and a required second approval will stop nearly every version of this scam — no special software needed.

A few fair questions

Can we tell a cloned voice by ear?

Not reliably. Some copies have a flat or robotic edge, but many don’t, and pressure makes people miss it. Don’t rely on your ear — rely on a callback rule.

Isn’t this only a big-company problem?

No. Smaller firms are easier targets because they often lack a second-approval rule, and one person may control payments. That’s exactly the gap these scams exploit.

Do insurers ask about this?

Increasingly, yes. Wire-verification steps and social-engineering coverage show up on renewals. Our cyber-insurance renewal checklist explains what to expect.

Want help setting a payment-verification rule your team will actually follow? Book 15 minutes with Wayne Libonati, President & CEO. Prefer to start on your own? Score your current IT relationship in about 3 minutes.

Wayne Libonati is President & CEO of Performance Connectivity, Inc. (PCI), the Purchase, NY firm he co-founded in 1997. He advises Westchester and Fairfield County business leaders on technology, risk, and AI.

← All insights

30 Years — coming in 2027