In February 2024, an employee in the Hong Kong office of Arup, a global engineering firm, sat down for a video call with the company's UK-based CFO. The CFO asked her to authorize a series of urgent wire transfers tied to a confidential acquisition. Other senior colleagues she recognized were on the call too. She raised a few questions. They answered. She moved the money: $25 million, across fifteen transactions, before anyone realized none of the people on the call were real. [SCMP]
Every face on that call was a deepfake. Every voice was cloned. The whole meeting was synthetic except for her.
This is what voice-clone business email compromise looks like at the high end. And the same technology has rolled downhill fast enough that the attack now runs against accounting clerks at small businesses with no special preparation and no Hollywood-grade rendering. Just a laptop and three seconds of audio scraped from a LinkedIn video.
The Numbers
The FBI's Internet Crime Complaint Center logged $20.9 billion in losses in 2025, a 26% jump from the year before. Business email compromise alone accounted for $3 billion. AI-related complaints, tracked for the first time as a separate category, came in at 22,000-plus complaints and nearly $900 million in losses. [IC3 2025]
BEC is not a phishing problem anymore. It is a phishing problem with a sequel.
The classic version is well-known: an attacker compromises or spoofs an executive's email, sends a wire-transfer request to someone in finance with the right tone and the right urgency, and the money moves. Defenders learned. Companies trained. Many added a verification step: "For any wire over $X, call the requester back and confirm verbally before authorizing."
That verification step was the protection.
It is no longer the protection.
How the Attack Now Works
The new pattern has two halves.
First, the email. Same as before. Spoofed or compromised executive account, urgent request, plausible context (acquisition, vendor change, payroll exception). Often timed for Friday afternoon, end of quarter, or the day before a holiday.
Then, the call. The finance employee follows the verification policy and calls back, sometimes to a number the attacker provided in the email, sometimes to the executive's real number that the attacker briefly hijacked through SIM swap or call forwarding. The voice on the line is the executive's voice. It paces correctly. It uses the right cadence. It answers a few of the employee's softball clarifying questions ("Yes, I'm in the airport, can you hear me?") and then closes the loop with the same authorization the email asked for.
The employee follows policy. Policy says the call confirmed it. The wire goes out.
The "confirmation" used to be the firewall. Now the confirmation is the attack.
How Cheap This Has Become
Voice cloning used to require minutes of clean audio and significant compute. Modern commercial tools clone a usable voice from three to ten seconds of source material and run on a laptop. Open-source models go lower than that.
The audio is everywhere:
- Conference talks and webinars on YouTube.
- Podcast appearances on the executive's own marketing trail.
- Sales demo videos on the company website.
- LinkedIn video posts.
- Press interviews, earnings calls, panels.
- The executive's own outgoing voicemail message.
If your CEO has done any media in the last five years, an attacker can have a working clone of their voice inside an hour.
This is not a Fortune 500 problem. The voice of a small-business owner from a single chamber of commerce video appearance is sufficient. The voice of a mid-market CFO from one industry conference recording is sufficient.
What Stops Working
A handful of controls that organizations relied on for years no longer carry their old weight:
Voice verification by itself. If the policy is "call the requester back and confirm verbally," the attacker has already planned for the call. The clone sounds like the executive because it is the executive's voice, just driven by someone else.
Caller ID. Spoofing has been trivial for fifteen years. The fact that "Bob CEO" appears on the screen during the call is not evidence that Bob is calling.
Urgency-based decision-making. Every BEC attack runs on urgency. If the policy can be bent because someone senior is annoyed, the policy is decorative.
Generic awareness training. Programs that train employees to "look for grammar errors and unusual greetings" do not prepare anyone for a call from their boss's actual voice.
What Actually Works
The fix is mostly process, not technology. Three changes, in order of impact:
1. Out-of-band callback to a pre-registered number. If a wire transfer over the threshold is requested, the verifier does not call the number that just called them. They do not call the number on the email. They call the executive's number from the company's HR system or directory. A number the attacker did not get to choose. This single change defeats the most common voice-clone BEC attack pattern outright.
2. A second-channel confirmation. An additional channel that the attacker has not also compromised: in person, internal chat from a verified account, or a video call initiated by the verifier (not the requester). The principle: the verification has to use a channel the attacker does not control.
3. Pre-registered code words for high-value transfers. Sounds dated. Works. A short phrase, agreed quietly between the executive and the finance team, never sent over email, never spoken in any recorded setting. The clone does not have it. If the voice on the line cannot produce it, the wire stops there.
None of these require new software. All of them require leadership to make the policy and back the people who follow it, especially when the call sounds urgent and the voice sounds like the boss.
The Leadership Question
The hardest part of this fix is not technical. It is cultural.
An accounting clerk who calls the CEO's wife at home to verify a wire is doing exactly the right thing. If that clerk gets snapped at the next morning for being slow or paranoid, the policy dies on the spot. The next attack walks straight through.
Leadership has to do two things at the same time: set the policy, and absorb the friction the policy creates. Praise the verifier when they delay a real transfer. Praise them louder when they delay a fake one. The first time leadership lets impatience override the verifier, the protection is gone.
The Arup employee in Hong Kong followed her policy. The policy was just a video call. The attackers built one.
The version of the policy that survives 2026 is the one that makes the verifier the last word, on a channel the attacker doesn't get to choose.


