Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Deepfake and AI Voice Scams: When the Fake CEO Sounds Completely Real

In short

AI can now clone a voice from a few seconds of audio and fake a video call convincingly. Criminals use this to impersonate a CEO or supplier and rush staff into paying fake invoices. The fix is not high-tech: an agreed call-back rule and a private code word beat even a perfect deepfake, because a fake voice cannot pass a check it does not know about.

The voice on the phone is your boss. Except it isn’t.

Imagine your finance assistant takes a call. It is the managing director — same voice, same manner, clearly in a hurry. There is a confidential deal closing today, the money must go out now, here are the account details, please keep it quiet. Everything about the call feels right.

Every part of it can now be faked. Artificial intelligence can clone a person’s voice from a short audio clip — a snippet from a webinar, a voicemail greeting, a podcast, a video posted on social media. A few seconds can be enough. The result is a phone call that genuinely sounds like your boss, because in every way that matters to the ear, it is.

This is the newest twist on an old crime, and it makes an already dangerous scam far harder to spot.

Why this supercharges BEC

Business email compromise — often called CEO fraud — is where a criminal impersonates a senior person or a trusted supplier to trick staff into paying a fake invoice or changing bank details. For years the weak point of these scams was doubt: a slightly odd email, an address that was almost-but-not-quite right, a niggling feeling that something was off.

Deepfakes remove that doubt. When the request arrives in a familiar voice — or even on a video call with a familiar face — the natural human check disappears. You are no longer squinting at an email address; you are listening to someone you know and trust.

A deepfake cannot supply a secret it was never told, so the scam collapses on a single question.

The uncomfortable truth is that you can no longer treat a voice, or even a face on a screen, as proof of who you are dealing with. That sounds alarming. The good news is that the defences are refreshingly low-tech.

The defences that actually work

You cannot out-clever an AI voice clone by listening harder. Instead, you beat it by adding a check the fake cannot pass — something outside the call itself.

1. The call-back rule

Make it an unbreakable policy: any request to move money or change bank details is confirmed by calling the person back on a number you already trust. Not the number that just called you. Not a number in the email. A number from your saved contacts or a past, verified record.

This works because the criminal does not control your trusted contact route. A perfect voice clone is powerless if your assistant simply says “of course — I’ll call you straight back on your usual number to confirm,” and then does. The scammer cannot answer a phone they are not holding.

2. An agreed code word

Agree a private word or short phrase, known only to your team, for confirming urgent or unusual requests. If someone calls claiming to be the boss with a rushed payment, staff ask for the code word before acting.

A deepfake can copy a voice, but it cannot know a secret it was never told. One simple question — “what’s our word?” — and the whole illusion falls apart. Keep the code word out of emails and away from anything public, and change it if it is ever used in a real situation.

3. A firm dual-authorisation process

Require two people to approve any payment over a set amount, or any change to supplier bank details. Two humans and a mandatory second signature is a genuine obstacle, and it means no single rushed employee can be pressured into moving money alone. This pairs naturally with the payment-verification habits covered in our guide to stopping invoice fraud.

4. Permission to pause

Deepfake scams run on urgency — the deal is closing, the money must go now, do not tell anyone. Make it explicit and safe for staff to slow down. Nobody should ever fear getting into trouble for verifying a payment, even from the most senior person in the business. A real request survives a five-minute check. A scam does not.

What to watch for

Even a convincing deepfake usually comes wrapped in the familiar signs of a scam:

  • Extreme urgency — it has to happen right now, today, before the end of the call.
  • Secrecy — “don’t mention this to anyone,” which conveniently prevents the one conversation that would expose the fraud.
  • A change of the normal process — a new account, a different channel, a request that skips the usual approvals.
  • A reason you cannot verify the usual way — “I’m about to go into a meeting, just sort it.”
  • A brand-new or unusual number for someone you know.

Any one of these should trigger your call-back rule, regardless of how real the voice sounds.

Preparing your team

The most important step is simply telling your staff this is now possible. Many people still assume that hearing a familiar voice is proof enough — a belief that made perfect sense a few years ago and is now a genuine liability. A short, honest conversation that says “if you ever get an urgent payment request by phone or video, we always call back and always ask for the code word, no exceptions” is worth more than any gadget.

Build these rules in before you need them. When a deepfake call does arrive, the moment of pressure is the worst possible time to invent a process. A calm, agreed routine turns a frightening scam into a non-event.

How DACROS can help

AI voice and video scams are unsettling precisely because they target trust rather than technology. The defence is a sensible mix of clear procedures, staff awareness and solid cyber-security foundations — the kind of quiet, practical protection we put in place for businesses across Leeds and Yorkshire every week. If you would like help writing a call-back policy, agreeing verification steps or training your team to handle these calls with confidence, get in touch for a straightforward chat.

Frequently asked questions

Can AI really clone someone's voice from a short clip?

Yes. Modern tools can produce a convincing copy of a person's voice from a small sample — sometimes only a few seconds pulled from a video, voicemail, podcast or webinar. That is enough for a criminal to make a phone call that sounds like your boss or a supplier, which is why voice alone can no longer be treated as proof of who is calling.

How is a deepfake scam different from a normal phishing email?

The goal is the same — trick someone into moving money or sharing access — but the delivery is far more convincing. A deepfake adds a familiar voice or face to the request, which removes the doubt a suspicious email might raise. It is best thought of as business email compromise with a powerful new disguise bolted on.

What is a call-back rule and why does it work?

A call-back rule means that any request to pay money or change bank details must be confirmed by phoning the person back on a number you already trust — not the number they called or emailed from. It works because the criminal does not control your trusted contact route. Even a flawless voice clone cannot answer a phone it is not holding.

What is a verification code word?

It is a simple pre-agreed word or phrase, known only to your team, used to confirm an unusual or urgent request. If a caller claims to be the boss asking for an urgent payment, staff ask for the code word. A deepfake cannot supply a secret it was never told, so the scam collapses on a single question.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.