Deepfakes and the New Face of Financial Fraud
In early 2024, a finance employee at a multinational firm joined what looked like a routine video call with the company's CFO and several colleagues. Everyone on screen looked and sounded exactly right. By the end of the call, the employee had authorized transfers totalling roughly US$25 million. Every participant except the victim was a deepfake.
That case was a watershed. Synthetic media has moved from novelty to a practical, high-yield fraud tool — and the technology has only become cheaper and more convincing since.
Why deepfakes work so well
Traditional business email compromise (BEC) relies on a forged message and the hope that the target won't pick up the phone to check. Deepfakes remove that safety net. When the "voice on the line" or the "face on the call" matches your boss perfectly, the instinct to verify disappears.
Voice cloning from seconds of audio
Modern voice-synthesis tools need only a short sample — often just a few seconds pulled from a conference talk, a podcast, a voicemail greeting, or a social media clip — to produce a convincing clone. Attackers then place "urgent" phone calls impersonating an executive, a supplier, or even a family member.
Real-time video impersonation
Live face-swapping during video calls is now achievable on consumer hardware. Combined with a cloned voice and a spoofed caller ID, it creates a multi-sensory illusion that's extremely hard to challenge in the moment.
The targets aren't just giant corporations
It's tempting to assume this is a Fortune-500 problem. It isn't. Small and mid-sized businesses are attractive precisely because they rarely have strict payment-verification controls. A cloned call to a bookkeeper, an "emergency" supplier change, a fake director approving an invoice — these scale down to organizations of any size, in any market.
How to verify reality
The defense against synthetic media isn't better eyes or ears — it's process. Authenticity must be confirmed through a channel the attacker doesn't control.
- Out-of-band callback: for any payment or sensitive request, hang up and call back on a known, pre-saved number — never the number that contacted you.
- Verification code words: agree on a shared secret phrase for high-value approvals between executives and finance staff.
- Dual authorization: require two independent people to approve transfers above a threshold.
- Slow the urgency: "urgent and confidential" is the single most common pressure tactic — make it a trigger for extra checks, not fewer.
Key takeaways
- Seeing and hearing is no longer believing — deepfake voice and video are cheap and convincing.
- Build out-of-band verification into every payment and account-change process.
- Treat urgency and secrecy as red flags that demand more scrutiny.
- Train finance and executive teams specifically on impersonation scenarios.
Sources
- CNN Business — Finance worker pays out $25 million after video call with deepfake "CFO" (the Arup case, Hong Kong, 2024).
- Deloitte Center for Financial Services — 2024 poll: 25.9% of executives reported one or more deepfake incidents targeting financial and accounting data in the prior year.
Protect your finance team from impersonation fraud
ProVaSec helps you build verification controls and train staff against deepfake-enabled social engineering.
Talk to our team →