Deepfake and voice-clone fraud controls

The chief financial officer is on the video call. The voice is right, the face is right, the urgency is right, and the request is to release a payment today. Every instinct the organization has trained into its people says this is the person they think it is. None of those instincts is a control any more.

The honest technical position

Detection tooling degrades as synthesis improves. That is not pessimism about any particular product; it is the structure of the problem, in which the detector and the generator improve against each other and the detector is always responding to what already exists. Real-time spotting of a fake on a call is not the control. Verification on a separate channel is.

This is good news, because a process control does not degrade. A callback to a number from your own directory works the same way against a perfect fake as against a clumsy one, and it keeps working when the technology moves again.

The threat itself is documented by Canada’s Centre for Cyber Security in ITSAP.00.041, which states that threat actors use AI in scams and fraudulent campaigns against individuals and organizations, and that they can craft targeted spear-phishing attacks more frequently, automatically, and with a higher level of sophistication.

The processes we review

The scope is defined by consequence, not by department. Wherever an instruction from a recognizable person can cause something that is hard to reverse:

  • Money moved. Payment release, wire approval, and the change of supplier bank details, which is the version that does the most damage because it survives to the next invoice.
  • Credentials reset. Service-desk password and multi-factor resets, where a convincing voice and a plausible emergency are the entire attack.
  • Access granted. Roles, permissions and system access issued on an urgent verbal request.
  • Data released. Records, files or personal information sent to someone who sounded like the person entitled to them.

Finance is the obvious target and not the only one. Any process where an instruction from a recognizable person causes an irreversible action is in scope — credential resets at the service desk, data released to a caller, supplier bank details changed, access granted for an urgent project. The service desk is usually the least protected of the four and the most often targeted.

Out-of-band verification

One rule carries most of the weight: never verify on the channel the request arrived on. A callback to the number in the caller’s message verifies nothing. A callback to the number in your own directory verifies the person.

Designing it well means deciding which requests require it, which directory is authoritative and who may change it, what the responder does when the callback is not answered — the answer is that the request waits, and that has to be explicit or urgency will override it — and how the verification is recorded. The recording matters twice: it is the evidence afterwards, and it is what makes the control visible enough to be audited internally rather than quietly skipped.

Challenge procedures for high-value authorizations

Above a threshold you set, a callback is supplemented by a challenge: a shared phrase, a question with an answer no public source holds, or a confirmation through a second authenticated channel. These are simple to design and easy to get wrong, so the review covers how the phrase is distributed and rotated, what happens when someone forgets it, and the failure mode where a helpful employee reminds the caller what the procedure is.

Dual authorization does similar work by a different route, and is often the better answer for payments: two people, two devices, and no single conversation that can move money.

Onboarding and identity verification

Remote hiring and remote onboarding create a second exposure with the same root: an identity asserted over video. The review covers how identity is established before an account exists, whether document verification is performed against an authoritative source rather than a submitted image, how the first credential is delivered, and what the first thirty days of access actually permit.

Where identity and workplace controls generally are the concern, see identity and workplace security.

Staff guidance and the exercise

Awareness training asks people to detect something people cannot reliably detect. This work changes the process instead, so that an instruction arriving on any channel has to be confirmed on a different one before anything irreversible happens. The guidance that goes with it is short and procedural: which requests always require out-of-band verification; that urgency is a reason to verify rather than to hurry; that a request to bypass the process is itself the signal; and an explicit, written assurance that nobody will be penalized for delaying a genuine executive request by fifteen minutes. That last sentence is the one that makes the rest work.

The exercise is a facilitated scenario rather than a surprise: the group is walked through an urgent request that arrives with a convincing voice or video, and traces what each person would actually do, step by step, against the process as written. The value is in the gaps it finds — the deputy who is not sure which directory is authoritative, the out-of-hours path with no second approver, the supplier-details change that turns out to require no verification at all.

Where an EU nexus exists

For organizations with an EU footprint, the EU AI Act, Regulation (EU) 2024/1689, places transparency obligations on providers and deployers of certain AI systems, including a duty to disclose AI-generated or manipulated image, audio or video content that would falsely appear authentic. That is a labelling obligation on legitimate deployers rather than a defence against fraud — criminals do not label their output — so it belongs in your compliance planning rather than in your control set. Whether and how it applies to a given organization is a question for its counsel.

What you receive

  • A process review of the payment, credential, access and data-release paths, naming where an instruction alone is currently sufficient.
  • A verification design: which requests require out-of-band confirmation, against which directory, with what recorded and what happens when confirmation fails.
  • Staff guidance written as procedure rather than as awareness material, short enough to be followed under pressure.
  • Exercise findings, with the gaps the scenario exposed and the owner for each.

We do not recommend a detection product, because the control that holds is not detection. Synthesis improves faster than detection does, and a control whose effectiveness depends on staying ahead of that race is a control with an expiry date nobody can read. Where the incident has already happened, the organizational response is covered in incident response readiness and the first 24 hours of an incident.

How the work is bounded

The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.

SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.

Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.

Questions we are asked

Can you tell us which detection tool to buy?

We do not recommend a detection product, because the control that holds is not detection. Synthesis improves faster than detection does, and a control whose effectiveness depends on staying ahead of that race is a control with an expiry date nobody can read.

Does deepfake fraud only matter for finance teams?

Finance is the obvious target and not the only one. Any process where an instruction from a recognizable person causes an irreversible action is in scope — credential resets at the service desk, data released to a caller, supplier bank details changed, access granted for an urgent project.

What does the exercise involve?

The exercise is a facilitated scenario rather than a surprise: the group is walked through an urgent request that arrives with a convincing voice or video, and traces what each person would actually do, step by step, against the process as written.

How is this different from awareness training?

Awareness training asks people to detect something people cannot reliably detect. This work changes the process instead, so that an instruction arriving on any channel has to be confirmed on a different one before anything irreversible happens.

Test the process, not the video

Describe how a payment, a credential reset or a data release is authorized today. The reply says where the instruction alone is currently enough.

Discuss a scope