fbpx

What Happens When Seeing and Hearing Someone Is No Longer Proof of Identity?

The rise of deepfake vishing means AI social engineering training needs a complete rewrite. Here’s what SMB leaders must do.

What Happens When Seeing and Hearing Someone Is No Longer Proof of Identity?

Key Takeaways:

How are attackers using AI voice cloning to trick employees?
How can employees verify suspicious voice requests?
What policies reduce AI-powered fraud risk?

Key Takeaways:

  • How are attackers using AI voice cloning to trick employees?
  • How can employees verify suspicious voice requests?
  • What policies reduce AI-powered fraud risk?

If your CFO received an urgent call from someone who sounded exactly like you and requested an emergency supplier payment, would they stop to verify the request or transfer the money?

That question has become a real business risk.

Some AI voice-cloning tools can create convincing imitations from short audio samples, making public recordings of executives and employees valuable to fraudsters.. Criminals are using technology to impersonate executives, vendors, and trusted partners in an effort to steal money, credentials, and sensitive information.

Many businesses still train employees to recognize phishing emails. But AI-powered social engineering has expanded well beyond the inbox. Employees now need clear verification procedures for phone calls, voice messages, collaboration tools, and any request involving money or sensitive data.

This article explains how AI social engineering threats are evolving and the practical steps SMB leaders can take to reduce their risk.

The New Reality of AI Cyber Security Threats

CrowdStrike’s 2026 Global Threat Report dubbed 2025 the “Year of the Evasive Adversary,” noting that attackers prioritized stealthy attack methods. AI cybersecurity threats surged 89% year-over-year, with many adversaries leveraging the technology to evolve their tradecraft.

So, how are adversaries using AI for social engineering?

Attackers aren’t limiting themselves to phishing emails anymore. They’re increasingly turning to vishing (voice phishing), where they use phone calls to trick employees into transferring money, sharing credentials, or revealing sensitive information.

Deepfake vishing takes that tactic a step further. Instead of speaking in their own voice, cybercriminals use AI to clone the voice of someone the victim already trusts. A phone call that appears to come from your CEO, controller, or key vendor may actually be an AI-generated impersonation designed to pressure employees into acting before they have time to verify the request.

So, how are fraudsters pulling this off? 

It’s simpler than you think. 

A scammer targeting your business will first look for a short audio or video clip of you or someone on your team from a public source. It could be anything from something shared on a linked post, a company webinar, a podcast, or social media. 

Once they have access, they feed it into an AI voice-cloning tool, and in just a few minutes, it generates a recognizable voice that says whatever the scammer types. 

No technical skill required, no expensive equipment. Just a few seconds of audio or video and a plan. That’s the new reality of AI cybersecurity threats.

Explore the Nine Steps of Implementing an Effective Cybersecurity Plan.

One Engineering Firm Lost $25.6 Million to a Deepfake Scam

In early 2024, British engineering firm Arup fell victim to one of the most elaborate AI cybersecurity threats. 

Here’s how it played out. 

One day, a finance employee at their Hong Kong office received a request to join what seemed like a routine video call with the CFO and other colleagues. 

He’d actually suspected an earlier phishing email, since it required a secret transaction. 

However, those doubts faded once he saw and heard people on the call who looked and sounded exactly like colleagues he recognized. 

Here’s the plot twist: It turns out that every person on that call, aside from the employee, was an AI-generated deepfake. 

The unwitting employee transferred $25.6 million across 15 separate transactions, only realizing what had happened after checking in with headquarters. 

This employee wasn’t careless. He was skeptical at first. But a familiar face and voice, in real time, overrode his instincts. Which underscores why traditional social engineering training isn’t enough in the age of AI.

So if seeing and hearing someone can no longer confirm their identity, what can? That’s what we’ll cover next.

How Can Employees Verify Suspicious Voice Requests?

Use these three tips to verify suspicious voice requests:

Tip #1: Establish Verbal Safe Words

Use private code words only your employees or partners know to confirm identity during any high-stakes request. 

Why? While an AI clone can mimic a voice perfectly, it can’t guess a password it was never trained on. 

Tip #2: Implement a Callback-Only Validation Policy

Never confirm a financial request using the phone number or contact info provided in a suspicious call or email. Hang up and call the person back using a number your business already has on file.

Tip #3: Enforce a Secondary, Multi-channel Approval Process

Never let one channel be the sole basis for moving money. Always require a second, independent confirmation via a different communication method before funds are transferred. 

Private equity firm Adams Street Partners has built its wire fraud defense around this exact mindset. 

Mark Lutostanski, one of the principals overseeing cash management at the firm, says they treat every wire instruction change as potentially fraudulent and adopt a “guilty until proven innocent” stance until it’s independently verified. 

You, too, can borrow from this playbook.

The Non-Technical Fix: What Policies Reduce AI Fraud Risk?

Here are two simple policies to reduce AI fraud risk:

Policy #1: Multi-Person Sign-offs

No single employee, regardless of seniority, should approve a large transfer alone. Require at least two people to independently confirm any unusual or urgent request before money moves. 

Policy #2: A Culture That Rewards Verification

Build a workplace where pausing to verify is celebrated, not punished, even if it’s a false alarm that could delay a legitimate payment. That small inconvenience is nothing compared to the alternative. 

Learn More About  Building a Cybersecurity Culture in Your Organization.

Get Your Free AI Social Engineering Threats Cybersecurity Consultation

AI voice cloning is moving fast, and it won’t slow down anytime soon. 

If your current social engineering awareness training still centers on “spotting bad grammar” or “checking for suspicious links,” it’s time for an honest conversation about where the real risk lies in the age of deepfake vishing and other rapidly evolving AI cybersecurity threats.

Contact Attentus Technologies to help you design a modern, foolproof cybersecurity implementation plan that protects your organization from evolving AI threats.

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY

FILL IN THIS FORM TO DOWNLOAD THIS CASE STUDY