Deepfake CFO Fraud: How Voice-Cloning Scams Work
Deepfake CFO fraud is an attack in which criminals use AI-generated audio or video to impersonate a company’s chief financial officer or other senior executive and pressure an employee into wiring money or disclosing sensitive financial data. The technology now requires as little as 3 seconds of publicly available audio to produce a recognizable voice clone, and a few minutes of audio to produce one convincing enough to fool a live listener. Finance teams that rely on a phone call or video conference to verify a wire transfer request are no longer protected by that step alone. The controls that stop traditional business email compromise do not stop a real-time voice or video impersonation.
How Deepfake CFO Fraud Works
The mechanics of a deepfake CFO fraud attack follow a recognizable pattern, even as the underlying technology keeps improving.
Step 1: Reconnaissance
Attackers begin by harvesting audio and video of the executive they plan to impersonate. Earnings call recordings, conference keynotes, investor-day webcasts, LinkedIn posts, podcast appearances, and even short clips embedded in press releases all provide raw material. Because executives at mid-market companies often have a measurable public footprint, a convincing voice clone requires very little source material to produce. Research published by McAfee found that as little as 3 seconds of audio can produce a voice clone with roughly 85% accuracy. This is an industry research finding rather than a fixed technical limit, and higher-fidelity clones capable of sustaining a longer conversation can be built from a few minutes of public audio.
Step 2: The Approach
In most documented cases the attack starts with a business email compromise message. An email, sent from a spoofed or lookalike domain, instructs an accounts payable specialist, controller, or junior finance employee to expect an urgent call from the CFO about a confidential wire transfer. The urgency framing is deliberate: it creates a mental shortcut that makes the follow-up call feel like confirmation rather than a reason to pause.
Step 3: The Call or Video Conference
The cloned voice then calls the employee by phone, or the attackers schedule a video conference populated with AI-generated avatars of multiple executives to project broader authority. This is precisely what happened in the now-documented Arup case: a finance employee at the engineering firm’s Hong Kong office was invited into a video call where the apparent CFO and several colleagues, all of them deepfakes, directed 15 wire transfers totaling $25.6 million. Every participant on that call was AI-generated. The employee did not realize the call was fake until contacting the real corporate headquarters afterward.
Step 4: The Transfer
Once the employee believes they are speaking with a legitimate executive, the psychological barrier to authorizing a large transfer is largely gone. Urgency, confidentiality instructions (“do not discuss this with your manager yet”), and apparent authority combine to suppress the instinct to slow down and verify.
Why This Threat Has Escalated Sharply
Deepfake CFO fraud is not new, but its scale and accessibility have changed dramatically in the past two years.
The FBI’s 2025 Internet Crime Complaint Center (IC3) report logged 22,364 AI-related fraud complaints with nearly $893 million in reported losses for that year alone. Business email compromise, the broader category that includes voice and video impersonation attacks, accounted for $3.05 billion in reported losses across 24,768 complaints in 2025, up from $2.77 billion the prior year. Within that category, the FBI attributed more than $30 million in losses specifically to BEC schemes with a confirmed AI component, the first year the bureau tracked AI as a distinct descriptor. The overall average BEC loss in 2025 was roughly $123,000 per reported complaint, and the FBI has cautioned that AI-enabled incidents are widely underreported.
In November 2024, FinCEN issued Alert FIN-2024-Alert004 warning financial institutions about the growing use of AI-generated deepfake media to circumvent identity verification, authentication, and due diligence controls. That alert followed a surge in suspicious activity reports filed by banks and other financial institutions describing deepfake-enabled fraud attempts. The FinCEN alert remains the clearest federal acknowledgment that this is a systemic risk, not an isolated technical novelty.
Deepfake-as-a-service tools have further lowered the barrier. Criminal groups no longer need in-house machine learning expertise. Off-the-shelf platforms, some marketed as entertainment products, can produce real-time voice conversion in under a minute for a few dollars per session. What began as a sophisticated nation-state capability is now available to organized crime and opportunistic fraudsters.
Who Is Targeted
Finance teams are the primary target because they hold the combination of payment authority and a cultural norm of executive deference on sensitive financial matters. The employee who authorized the Arup transfers was not negligent by conventional standards. The company had verification procedures, but those procedures assumed that a video call with familiar faces was trustworthy.
Mid-market companies are disproportionately at risk for two reasons. First, they tend to have thinner internal controls than large public companies: fewer segregation-of-duty layers, less investment in cybersecurity tooling, and smaller finance teams where one person may hold both approval and execution authority. Second, their executives are public enough to have harvestable audio and video online, but not prominent enough to have security teams actively monitoring for impersonation attempts.
Controllers, accounts payable managers, and treasury staff should treat any out-of-band wire request, meaning a request that arrives outside a pre-established payment workflow, as high-risk regardless of who appears to be asking.
Controls That Actually Work
The Arup case illustrated the core problem: traditional verification (call back the person who sent the email, or join a video call to confirm) is no longer sufficient when the call itself can be faked. Effective controls need to account for that possibility.
Require a Callback to a Known Number
Before any wire transfer above a defined threshold is released, the approving employee must call back the requesting executive using a phone number on file in the company directory, not a number provided in the request itself. This single step breaks the attack chain in most scenarios, because it requires the attacker to also control the executive’s actual device.
Establish Code Words and Duress Signals
Some companies now maintain shared verbal passphrases for high-value payment approvals: a word or short phrase the CFO and finance team agree on in advance, in person or through a secure channel. An attacker who has not been briefed on the passphrase cannot complete the authentication. This is low-cost, requires no technology, and is directly analogous to the callback procedures long used in wire fraud prevention.
Apply Dual-Authorization on Wire Transfers
No single employee should have the authority to initiate and approve a large wire transfer. A second approver, reachable independently, must confirm before funds move. This control is standard in well-designed treasury policies and should be applied regardless of how urgent or sensitive the requesting executive claims the transaction to be.
Train Employees to Recognize Pressure Tactics
The urgency, secrecy, and authority elements of these attacks are not accidental. Employees need explicit training that an executive asking them to bypass controls is itself a red flag, and that slowing down on a suspicious request will not result in professional consequences. Finance teams need psychological permission to say “I need to verify this through our standard process before I can release these funds.”
Invest in Lightweight Technical Detection
Real-time deepfake detection tools are now commercially available and integrate with videoconferencing platforms. These tools flag audio artifacts, inconsistent lighting, and unnatural facial movement patterns that are invisible to an untrained eye but detectable algorithmically. They are not foolproof, but they add a layer of friction that deters lower-sophistication attacks.
The NIST Digital Identity Guidelines provide a framework for risk-tiered identity verification that finance teams can adapt: higher-value, less reversible transactions warrant stronger verification requirements, including out-of-band confirmation through a channel the initiating party cannot control.
The Internal Controls Gap Most Companies Miss
Many mid-market companies have anti-fraud policies written for a world in which the primary risk was a rogue employee or a phishing email. Those policies typically address things like segregation of duties, dual approval thresholds, and email authentication (SPF, DKIM, DMARC). They do not address what to do when the CFO’s voice or face can be synthesized in real time.
A meaningful gap analysis should ask: at which points in our payment workflow does verbal or video confirmation from an executive substitute for, or override, a written policy control? Every one of those points is a potential attack surface under the deepfake threat model.
Modus’s advisory practice works with finance leaders to pressure-test payment controls against modern fraud vectors, including AI-enabled impersonation. A controls review that accounts for voice cloning and deepfake video will look meaningfully different from one written five years ago.
What to Do If You Suspect an Attack Is in Progress
If an employee suspects a call or video conference may not be genuine, the right response is to end the meeting politely, citing a technical issue if needed, and immediately contact the executive through a known channel, such as a direct call to their mobile number on file. Do not attempt to “test” the caller by asking trick questions. Sophisticated attackers prepare for this.
If a transfer has already been initiated, time matters enormously. The FBI’s IC3 Recovery Asset Team froze $679 million in BEC-related transfers in 2025 with a 58% success rate, but only when notified quickly. Contact your bank’s wire department immediately to request a recall, then file a complaint with the FBI’s IC3 at ic3.gov and notify your insurance carrier.
For companies with an outsourced CFO or fractional finance relationship, confirm that your service provider has current contact protocols in place and that staff know the difference between a verified out-of-band request and an in-meeting instruction.
Frequently Asked Questions
What is deepfake CFO fraud?
Deepfake CFO fraud is a type of business email compromise attack in which criminals use AI-generated audio or video to impersonate a company’s CFO or other executive in real time, typically to authorize fraudulent wire transfers. It goes beyond traditional email spoofing by using a cloned voice or synthetic video image on a live call, making the fraud much harder for employees to detect.
How do voice cloning scams work?
A voice cloning scam works in three stages: the attacker collects audio samples of the target executive from public sources (earnings calls, interviews, conference recordings), feeds that audio into a cloning tool to generate a synthetic voice model, and then uses that model to place a phone call or join a video conference posing as the executive. Modern tools can produce a convincing clone from as few as 3 seconds of source audio.
How much money has been lost to deepfake CEO and CFO fraud?
Documented losses are significant and growing. The FBI’s 2025 IC3 report recorded nearly $893 million in AI-related fraud losses and $3.05 billion in total business email compromise losses for 2025. The most cited single incident, the Arup engineering case, involved $25.6 million lost in a single day via a deepfake video conference in early 2024. Experts note that underreporting is widespread, so actual losses are likely much higher.
Can a video call really be faked?
Yes. The Arup case confirmed that a full multi-participant video conference, including multiple executives and colleagues, can be populated with AI-generated avatars that appear convincingly real to an employee who knows those people. The technology continues to improve. Detection requires either technical tools integrated into the videoconferencing platform or a verification step conducted outside the meeting entirely.
What is the single most effective control against voice cloning fraud?
The most effective single control is a mandatory callback to a known, pre-registered phone number before releasing any large or out-of-pattern wire transfer, regardless of what was communicated on a call or in a meeting. This control is free, requires no technology, and cannot be defeated by a cloned voice unless the attacker also controls the executive’s actual device.
Should companies report deepfake fraud attempts even if no money was lost?
Yes. Filing a complaint with the FBI’s Internet Crime Complaint Center (ic3.gov) even for attempted fraud helps investigators track patterns, identify criminal networks, and issue alerts that protect other businesses. FinCEN’s November 2024 alert was specifically informed by an increase in suspicious activity reports from financial institutions. Reporting near-misses contributes to collective defenses across the industry.
Filed under: Cybersecurity & Risk