United Kingdom flagIndependent UK business banking research
UK Business Banking Research · BanksGB
Business typesCards & expensesCash flowSecurityDigital bankingMerchant servicesFX & tradeInsightsAll topics
BanksGB · Security

Deepfake voice payment fraud: a familiar executive voice is no longer enough to approve money

A practical UK business guide to AI voice-clone payment scams covering executive impersonation, callback controls, payment phrases, verification and incident response.

AI-generated voice can imitate an executive, supplier or adviser closely enough to make an urgent payment request sound authentic. The National Cyber Security Centre has warned that attackers can increasingly use voice clones and deepfakes to trick people into revealing information or acting on false instructions, which makes process-based verification more important than voice recognition.

A realistic voice is evidence only that audio exists

Voice cloning can reproduce tone, accent and speaking style from short public recordings. Senior executives who appear in webinars, interviews or social media can provide enough source material for convincing impersonation.

Employees should not be expected to detect synthetic audio by ear. The control should assume the voice can be convincing and require an independent verification step.

Fraud scripts exploit secrecy and senior authority

The caller can claim an acquisition is confidential, a supplier will stop delivery or a director needs a transfer before boarding a flight. Those details are designed to stop the employee asking another colleague for confirmation.

Make secrecy itself a reason for stronger control, not weaker control. Confidential transactions can use pre-approved deal codes or known advisers without bypassing dual approval.

Verify through a separate channel

Call the executive back using a known stored number or contact them through the company's authenticated messaging system. Do not use a number provided during the suspicious call.

For material payments, require the normal second approver even after the voice is verified. One successful callback should not eliminate the company's ordinary financial controls.

Use transaction-specific verification, not static secret questions

A permanent family name or favourite sports team can be discovered publicly. Stronger processes use transaction context, pre-agreed deal identifiers or confirmation through a secure corporate system.

Rotate emergency verification methods after exposure. A secret phrase discussed openly on a compromised call is no longer secret.

Train assistants and finance staff together

Attackers can target executive assistants first because they know travel schedules and can create convincing context before calling treasury. Payment training should include everyone who can influence or initiate an urgent request.

Staff need explicit permission to challenge senior people. The control fails if an employee fears being criticised for calling the CEO back.

Treat suspected deepfake fraud as account-compromise risk too

If a voice scam uses real confidential transaction details, investigate whether email, calendar or messaging systems were compromised. The attacker may have more than public audio.

Contact the bank immediately if payment was released and preserve recordings, phone numbers, emails and chat evidence for security and law-enforcement review.

Worked example: a finance manager receives a voice call that sounds exactly like the CEO asking for £300,000 to a new lawyer account before a confidential acquisition closes. Instead of relying on voice recognition, the manager calls the CEO's stored mobile number and asks the second authorised director to confirm the deal in the corporate messaging system.

Keep pre-approved deal payment instructions in the transaction data room. If advisers and beneficiaries are already documented, a last-minute voice request to substitute bank details becomes easier to reject.

Review public executive audio as part of threat awareness, but do not try to remove every recording from the internet. Process resilience is more scalable than hoping attackers lack enough material to clone a voice.

Worked example: an attacker clones the voice of a managing director from a public webinar and calls an AP manager about a secret acquisition. The voice is convincing and uses real deal terminology obtained from a compromised email. The payment still fails because the company requires a separate secure message from the second deal approver and beneficiary details already stored in the data room.

Protect video calls too. A synthetic face or prerecorded clip can accompany a cloned voice, so seeing the executive on screen should not become the only verification control for a material payment.

Use payment-specific controls that remain useful even as AI quality improves. Dual approval, known beneficiary records and independently initiated callbacks do not depend on employees identifying subtle audio artefacts.

After an attempted deepfake, review what private facts the attacker knew. Accurate deal dates, adviser names or travel plans can indicate a compromised calendar or mailbox that needs separate incident response.

Pre-register beneficiary details for confidential deals with a limited group of authorised finance staff. A last-minute request to replace the lawyer, escrow or seller account should then stand out even when the voice requesting the change sounds exactly like a senior executive.

Record attempted deepfake incidents even when no money moves. Repeated targeting of one executive or deal can reveal that attackers have unusually detailed intelligence and justify stronger controls around that transaction.

Editorial Verdict

Deepfake voice technology weakens one of the oldest business controls: recognising who is speaking.

Replace voice trust with independent callback, secure-channel confirmation and dual payment approval. The goal is not to detect fake audio perfectly; it is to make a fake voice insufficient to move company money.

Sources

Keep the banking structure tied to the business model

Use the provider directory, comparisons and practical guides to narrow the questions before choosing products.

Start comparison