Select Page

The Voice on the Phone Sounds Like Your CEO. It Isn’t.

August 5, 2026 | Technology

Why deepfakes are the fastest-growing threat in business cybersecurity, and what to do about it.

You’ve probably seen the headlines: a finance team transferred $25 million to scammers after joining a video call where every “colleague” on screen, including the CFO, was a deepfake. At the time, it felt like an edge case. In 2026, it’s becoming a typical Tuesday.

Deepfake-enabled fraud has gone mainstream. The tools are cheap, the production quality is high and threat actors are using them in ways most organizations aren’t prepared for. We’re seeing it across every industry we support: healthcare practices targeted for patient data, manufacturers hit with vendor impersonation, financial services firms duped into authorizing wires that look completely legitimate on the surface.

The good news is that deepfakes aren’t unstoppable. The bad news is that defending against them takes a real shift in how your team thinks about identity, trust and verification.

Let’s break it down.

What’s changed

Generative AI moved voice cloning from “research demo” to “free app on the internet” in about 18 months. The same technology now produces convincing video impersonations, real-time face swaps on live calls and AI-generated text that mimics a specific person’s writing style. A determined attacker can clone an executive’s voice from a 30-second LinkedIn clip and absorb a year of public posts to mirror their tone. Yikes. 

What used to require a nation-state budget now requires simply a curious teenager with a credit card.

That changes the threat surface in a few key ways:

  • Email isn’t the only entry point anymore. Voicemails, video calls, Slack/Teams messages and texts can all be impersonated convincingly.
  • Trust signals you used to rely on are unreliable. Hearing your CEO’s voice is no longer proof it’s actually your CEO. Sorry!
  • Speed of execution matters more than ever. Deepfake attacks tend to be urgent by design (“approve this wire now, I’m about to board a flight”).

Where deepfakes show up in real organizations

Three patterns we see most often:

  1. Wire transfer fraud. A “CFO” calls AP, voice cloned, asking for an urgent payment to a new vendor. Sometimes it’s a “CEO” jumping into Teams briefly before “losing connection.”
  2. HR and payroll redirection. An “employee” messages HR asking to update direct deposit before payday.
  3. Executive impersonation in deals. A “client” or “vendor” joins a deal call, changes terms or extracts confidential information.

All three exploit the same vulnerability: humans trusting familiar voices, faces and speaking/writing styles.

What works for prevention

Defending against deepfakes is less about detection technology (which is improving but still imperfect) and more about process.

Verification protocols. Any financial, HR or sensitive request that arrives through one channel should require confirmation through a different, pre-established channel. If the “CFO” calls asking for a wire, you call them back at a known number. Always! This is the easiest thing you can do.

Out-of-band code words. Some organizations use simple, agreed-upon phrases for high-stakes requests. It feels old-fashioned. But it also works.

Layered email and identity security. Strong DMARC enforcement, MFA on every account that touches money or data and tight access controls remove the easy paths attackers love. Our Managed Email Security is built for this layer.

Awareness training that addresses deepfakes specifically. Most security awareness programs were built when phishing meant a typo-ridden email from a “Nigerian prince.” Modern programs need to address synthetic voice, video and AI-driven social engineering directly. Our Security Awareness Training is updated for this reality, and it’s one of the highest-ROI investments most clients make this year.

What to do if it’s already happened

If you suspect a deepfake-enabled incident, time matters. The wire transfer window is usually measured in hours. Engage incident response immediately, freeze affected accounts, notify your bank and preserve evidence.

Then debrief with your team. The goal isn’t blame. It’s closing the process gap, so it doesn’t happen again next quarter.

One last thing…

Deepfakes target executives specifically because of the access and authority they have. Executive Risk Management is becoming a category of its own and one of the areas our team spends meaningful time on with clients in 2026. 

If your organization hasn’t pressure-tested its verification protocols recently, this is the conversation to have. Don’t wait for the post-mortem to learn where the gaps are. Talk to one of our team members, and let’s make sure your employees are ready before they ever get a call.