By Garrett Kohlrusch | GK Data LLC
An urgent request can sound exactly like the person you trust and still be fraudulent. Generative AI has made convincing voice, text, and video impersonation easier to produce, but the underlying attack remains familiar: create urgency, borrow authority, and prevent the target from verifying the request independently.
The strongest defense is not learning to hear a synthetic voice. It is building a process that does not treat a voice, sender name, or video tile as proof of identity.
What AI changes
A short audio sample from a public video, voicemail, meeting, or social account can be enough to create a usable imitation. AI can also improve the grammar, timing, and context of phishing messages. That does not make every synthetic message perfect, but it removes clues many people once relied on.
The FBI has warned about malicious actors using AI-generated voice messages for impersonation. The Federal Trade Commission gives the same practical advice for voice-cloning scams: do not trust the voice by itself; contact the person through a number or channel you already know.
Signals that are no longer sufficient
- A familiar voice: audio can be generated or replayed.
- A familiar sender name: display names and lookalike domains can mislead at a glance.
- A familiar face: a video meeting can be manipulated, and an account participating in the call may itself be compromised.
- Knowledge of real context: an attacker may know vendor names, current projects, travel schedules, or invoice details from public sources or a compromised mailbox.
- Urgency from a leader: authority and time pressure are part of the pretext, not evidence that it is genuine.
Controls a small business can use now
Verify through a known channel
End the call or pause the conversation. Use a phone number, directory entry, or account already on record. Do not use contact information supplied in the suspicious message. A private verification phrase can supplement this process for a very small team, but it should not replace a known-number callback.
Require two people for financial changes
New bank details, wire transfers, payroll changes, gift-card purchases, and unusual refunds should require a second approver. The approval should occur through a separate trusted channel and leave a record. No executive should be able to waive this control merely by saying the request is urgent.
Keep a trusted contact directory
Maintain verified phone numbers for owners, financial staff, banks, payroll providers, important vendors, and IT support. Review them periodically and control who can change them.
Protect the accounts that provide context
Email, cloud storage, calendars, messaging, and accounting systems can give an attacker the details needed for a convincing pretext. Use MFA, separate administrator access, strong recovery settings, and alerts for new sessions, forwarding rules, payment changes, and mailbox delegation.
Write the escalation process down
Employees should know who to contact and that pausing an unusual request is expected, not insubordinate. A short written procedure works better under pressure than a security-awareness slogan.
Why this matters financially
Business email compromise is not limited to email. The FBI’s 2025 Internet Crime Report defines the category as scams involving compromised email accounts and other communication methods, including phone numbers and virtual meeting applications. Reported BEC losses exceeded $3 billion in 2025. Those figures represent reported complaints, not a prediction of what any one business will lose, but they show why payment verification deserves a real control.
What to do after a suspected payment scam
- Contact the financial institution immediately using a verified number and ask about recall or hold options.
- Preserve the email, message, call details, payment instructions, headers, and account activity.
- Reset and revoke affected accounts and sessions from a trusted device.
- Review mailbox rules, delegated access, recovery methods, and recent sign-ins.
- Report the incident through the appropriate law-enforcement and fraud channels, including the FBI’s IC3 when applicable.
Official guidance: FBI 2025 Internet Crime Report, FBI impersonation alert, and FTC voice-cloning advice.
GK Data does not sell generic anti-scam training. Our role is narrower: testing the web, API, network, cloud, identity, and recovery paths an attacker may use before or after impersonation. Review the Network and Cloud Security Review, the Web and API testing service, or contact GK Data with the systems you need assessed.
