Voice-clone and deepfake CEO fraud: the payment controls that stop it

Deepfake CEO fraud is stopped by payment process, not by spotting the fake. The controls that hold are a callback to a number you already had, two people approving every release, a separate check on any change of banking details, and a short cooling-off period for urgent requests. Each of them works the same whether the voice on the call is clumsy or perfect.

Can staff just learn to spot the fake?

As of September 2026, the Canadian Centre for Cyber Security states in ITSAP.00.166 that audio or video alone should not be considered proof of identity, and that requests involving sensitive actions should be confirmed by a second, independent form of communication. That is the whole design principle in one sentence.

The attack itself is old. The Canadian Anti-Fraud Centre describes frauds targeting businesses in which an apparent executive asks accounts payable for an urgent payment, or an apparent supplier sends new payment directions. A cloned voice or a video call only removes the doubt an odd email used to raise.

Which payment controls stop deepfake CEO fraud?

Five, listed from most to least valuable.

  • Callback to a known number. Hang up and call back on a number from your own directory or supplier master file, never one supplied in the request. The Cyber Centre’s vishing guidance says the same: do not use numbers the caller gives you or the phone’s own callback option. It also notes that caller ID can be spoofed.
  • Dual approval. Two people release any payment above a threshold you set, and the second approver was not the one who took the request. A fake then has to deceive two people independently.
  • A separate process for changed banking details. This is the variant that does the most damage, because a changed account quietly receives every later invoice too. Verify the change with a known contact at the supplier, and hold the first payment to the new account for an extra check.
  • A cooling-off rule. Urgency and secrecy are the attack. A written rule that no urgent, confidential or out-of-pattern payment is released the same hour gives staff permission to slow down.
  • Code words, as a supplement. Useful between people who call each other often. Never a replacement for the callback.

Where do these controls usually fail?

The common failure is not a missing policy. It is a policy with an exception for senior people, or one that lives with finance while the service desk, payroll and HR can still be talked into irreversible actions. The Anti-Fraud Centre’s advice is detailed payment procedures with verbal authentication for any urgent request or change in payment details. Apply it wherever a convincing request can move money, reset credentials or release data.

Do these rules apply to the executives themselves? Yes, and the executives have to be the loudest supporters of the rules. A policy that the chief executive is seen to bypass once is a policy nobody will enforce on the day a fake chief executive calls.

The weakest point is usually email. If an attacker can read or send from a real mailbox, every later message looks authentic, which is why email authentication is part of the same defence.

How do we test the controls before an attacker does?

A control you have never exercised is a control you are hoping works. Walk the finance and service-desk teams through a scenario: an urgent video call from the chief executive, a supplier letter with new banking details. Trace what each person would actually do against the procedure as written. That is a tabletop exercise, and the design work behind the controls is our deepfake and voice-clone fraud controls service.

If money has already moved: Call your bank immediately and ask it to recall or freeze the transfer, because speed matters more than anything else. Then involve counsel and your insurer, and report to your police of jurisdiction and to the Canadian Anti-Fraud Centre. The first day of any incident is covered in the first 24 hours.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Can people learn to spot a deepfake?

Not reliably, and a control should not depend on it. The Cyber Centre’s position is that audio or video alone should not be treated as proof of identity, so the control is verification on a separate channel, which works the same against a perfect fake as against a clumsy one. The guidance is ITSAP.00.166.

Is a code word enough?

A code word helps as a second factor for people who call each other often, but it is not a substitute for the callback. Code words leak, get written down and get reused, and one that has been spoken on a compromised call is finished.

Do these rules apply to the executives themselves?

Yes, and the executives have to be the loudest supporters of the rules. A policy that the chief executive is seen to bypass once is a policy nobody will enforce on the day a fake chief executive calls.

What if a payment has already gone out?

Call your bank immediately and ask it to recall or freeze the transfer, because speed matters more than anything else. Then involve counsel and your insurer, and report to your police of jurisdiction and to the Canadian Anti-Fraud Centre.

Where would a convincing fake get through?

Send us your current payment and bank-detail change procedure, even if it is a paragraph in an email. The reply says where a convincing fake would get through. More of our writing is indexed at writing.

Discuss a scope