Most people first heard about deepfakes through a phone call story. Someone gets a call from a family member in trouble, sends money, and learns later the voice was generated. It is real and worth knowing about. It is also the smallest version of this problem.

Synthetic media is not limited to audio, and it is not limited to one channel. A convincing fraud now assembles a whole identity: a face, a voice, a company, a document trail, and a conversation that holds together across email, text, and video. Harrison says it often, and it applies here more than anywhere: AI is the dumbest it will ever be today. Whatever the output quality is now, that is the floor. So any defense that depends on you noticing a flaw has a short shelf life. This piece is about what replaces it.

What the Technology Can Actually Do

We would rather be precise than dramatic, so we will stick to what the FBI has described publicly. Its December 2024 public service announcement on generative AI and financial fraud laid out how criminals were already using these tools.

  • Text. Criminals generate large volumes of fictitious social media profiles, produce messages faster to reach more targets, build content for fraudulent websites, and use AI translation, which the FBI notes eliminates grammatical errors.
  • Images. Realistic photos for fake profiles, plus what the FBI describes as “fraudulent identification documents, such as fake driver’s licenses or credentials.”
  • Audio. The FBI describes criminals generating “short audio clips containing a loved one’s voice to impersonate a close relative in a crisis situation, asking for immediate financial assistance.”
  • Video. The same announcement describes criminals generating “videos for real time video chats with alleged company executives, law enforcement, or other authority figures.”

Read that list as building blocks, not four separate scams. Combine them and you get something most small businesses are not ready for.

Where This Shows Up in a Normal Business Week

  • A vendor that does not exist. A working website, staff photos, a social presence, a phone number that gets answered. Everything checks out because everything was built to check out.
  • Invoices and documents that look right. Correct logo, correct formatting, correct project reference, different bank account. Since criminals can generate convincing identification documents, treat “they sent a scan of their ID” as weak proof.
  • A video call with a participant who is not real. The FBI has flagged real time video chats with alleged company executives. A quick call to confirm a wire is exactly the moment this targets.
  • Voicemail in a familiar voice. Worse than a live call, because you cannot ask a question. The FTC has warned consumers that when a call sounds like your boss or a family member, “you’re more likely to act.”
  • Phishing with nothing left to catch. Bad spelling and clumsy grammar used to be the tell we taught staff to watch for. That tell is gone.

For volume, the FBI Internet Crime Complaint Center’s 2025 Internet Crime Report recorded 191,561 phishing and spoofing complaints in 2025, plus 24,768 business email compromise complaints and $3,046,598,558 in reported losses that year. Not all of that involves synthetic media. The point is that impersonation fraud is already the main event, and these tools make it cheaper to run.

Why “Spot the Fake” Is a Losing Strategy

There is still useful detection advice. The FBI suggests looking for distorted hands or feet, unrealistic teeth or eyes, and indistinct or irregular faces in generated images, and listening closely to tone and word choice on a suspicious call. Teach that. It costs nothing and it catches some attempts.

But do not build your controls on it. The flaws you train people to notice are the ones fixed in the next version. Detection puts the burden on one employee, in one moment, usually under time pressure, which is the worst place to put a control. And it quietly turns into blame: when someone misses a fake, the story becomes that they should have been sharper. That is unfair and useless, because the next fake will be better than the one they missed. We wrote more about how attackers use these tools in AI-powered cyberattacks are getting smarter.

The Replacement: Verify Through a Second Channel

Here is the shift. Stop asking “is this real?” and start asking “have I confirmed it a different way?” A fake can be perfect inside the channel it arrives in. Controlling two channels at once is much harder.

The FBI’s own guidance is a version of this: “verify the identity of the person calling you by hanging up the phone, researching the contact of the bank or organization purporting to call you, and call the phone number directly.” The FTC gives consumers the same instruction on voice cloning: “call the person who supposedly contacted you using a phone number you know is theirs, and verify the story.” The FBI also recommends creating a secret word or phrase with your family to verify identity, which translates neatly to a business.

  1. Use a number you already had. Not the number in the email signature, not the number the caller gives you, not the number on the invoice. The number in your own records.
  2. Change the medium. Request by email, confirm by phone. Request by phone or video, confirm by message to a known address. Never confirm in the same thread.
  3. Agree on a verification phrase in advance. A word your finance team and leadership share for confirming unusual requests. Simple, offline, and effective against a voice that sounds exactly right.
  4. Ask something no record would contain. On a live call, a question about a detail never written down anywhere is hard for an impersonator to answer.
  5. Slow the transaction down. Urgency is the common thread in nearly all of these schemes. A required waiting period on new payment details costs you a day and defeats a whole category of fraud.

Make It a Process, Not a Personality Test

Second channel verification works because it does not depend on anyone being clever that day. It is a step in a procedure, like counting a cash drawer. Write it down and it stops being a judgment call.

  • Define which actions require verification. New or changed bank details, wires over a threshold, gift card purchases, payroll direct deposit changes, urgent credential resets.
  • Give people explicit permission to pause. Staff need to hear from ownership that verifying a request from the boss is never insubordination. If your culture punishes the pause, the policy is decorative.
  • Keep a verified contact list. Known good phone numbers for vendors and executives, maintained on purpose, so nobody improvises under pressure.
  • Practice it once. Walk through a fake urgent wire request in a staff meeting. Ten minutes and everyone knows the steps.
  • Know where to report. The FBI directs the public to its Internet Crime Complaint Center, and the FTC asks consumers to report fraud at ReportFraud.ftc.gov.

If your team is already nervous about AI, this is a good place to start, because it is concrete. We covered the broader version in how to actually prepare your team for AI without the hype.

The Bottom Line

Synthetic media has moved past the emergency phone call into vendors, documents, meetings, and voicemail. Detection advice is worth teaching, but it is a supplement, not a control. The durable answer is procedural: identity gets confirmed through a channel the requester did not choose, using contact details you already held, before money or access moves.

That approach does not expire when the technology improves. It works the same whether the fake is crude or flawless, which is what you want from a control you plan to rely on for years.

We help businesses across Denton County write these verification steps into how they actually operate, train staff without making anyone feel foolish, and put technical controls behind the policy. If you want a second set of eyes on your payment and approval process before someone else tests it, we are glad to help. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).