A finance employee at the engineering firm Arup joined a video call with the company’s CFO and several colleagues. Familiar faces, familiar voices. On that call, the employee was instructed to make a series of transfers, and sent $25 million. Every other person on that call was fake, generated by AI. CNN covered the case here.
When that story broke, it felt like a problem for billion-dollar companies. It is not anymore. The same technology now runs on cheap tools, needs only a few seconds of someone’s voice, and has moved downmarket to where the defenses are thinnest: small and mid-sized businesses.
This Is Now a Volume Business
Voice security firm Hiya surveyed over 12,000 consumers for its State of the Call 2026 report. The findings:
- 1 in 4 Americans say they received a deepfake voice call in the past 12 months
- Another 24% could not tell whether a call was a deepfake or a real person
- Put together, nearly half the U.S. population has either encountered AI voice fraud or cannot reliably detect it
Scammers used to need a convincing actor. Now they need a YouTube clip, a voicemail greeting, or a podcast appearance. A few seconds of audio is enough to clone a voice.
Why Small Businesses Are the Ideal Target
We wrote in AI-Powered Cyberattacks Are Getting Smarter that AI lowers the cost of running convincing attacks at scale. Voice cloning is that trend with a phone number. Small businesses make attractive targets for three reasons:
Trust runs on voice. In a 15-person company, hearing the owner’s voice IS the verification. There is no approval workflow to get in the way.
One person can move money. Many small businesses have a single bookkeeper or office manager who can wire funds or change payroll details on their own authority.
Voices are public. The owner is in marketing videos, on the company voicemail, maybe on local radio. The raw material is free.
The classic play looks like this: a call or voicemail that sounds exactly like the boss. There is urgency (“this closes today”), authority (“I’m telling you it’s fine”), and secrecy (“keep this between us for now”). The ask is a wire transfer, gift cards, a “vendor” banking change, or a payroll redirect. Every one of those ingredients should now be treated as a red flag, no matter how right the voice sounds.
The Defense Costs Almost Nothing
Here is the good news: this threat, powered by cutting-edge AI, is beaten by procedures older than the telephone.
1. Set a codeword. Pick a word or phrase known only to your leadership and whoever handles money. Any unusual request by phone must include it. A cloned voice cannot say a word it has never heard.
2. Verify on a known number. Any request to move money or change banking details gets a callback, to the number already in your contacts, never the number that just called. Thirty seconds ends the scam.
3. Two people touch every payment change. No single person, no matter how senior the voice on the phone, can authorize a new payee, a banking change, or an unusual transfer alone.
4. Make it safe to say “let me check.” Deepfake scams work because employees fear questioning the boss more than they fear fraud. Tell your team, explicitly and in writing, that verifying will never get them in trouble. The employee who slows things down is doing their job.
5. Train with real examples. The same team you have trained on phishing emails needs to hear that phishing has a voice now. Play a cloned-audio demo in a team meeting. Once people hear how good it is, the lesson sticks.
6. Add the technical backstops. Bank-side payment controls, dual authorization on wires, and multi-factor approval built into the payment process, not just the login screen.
The Question to Ask Yourself Today
If someone called your bookkeeper right now sounding exactly like you and asked for an urgent transfer, what would stop it?
If the honest answer is “nothing but their gut,” you are one convincing phone call away from a very bad week. The fix is a codeword, a callback rule, and a five-minute conversation at your next team meeting. Few security upgrades cost this little and block this much.
Want help putting verification procedures and team training in place before the phone rings? Contact us today.
Sources:

Comments are closed